<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[🚂 CyberExpress (newsletter Niebezpiecznika)]]></title><description><![CDATA[Najważniejsze wydarzenia ze świata cyberbezpieczeństwa z ostatnich godzin. Regularnie i zwięźle. ]]></description><link>https://niebezpiecznik.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!HMcS!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862c40a5-8ef8-4125-9157-6b4967d454a9_512x512.png</url><title>🚂 CyberExpress (newsletter Niebezpiecznika)</title><link>https://niebezpiecznik.substack.com</link></image><generator>Substack</generator><lastBuildDate>Mon, 15 Jun 2026 11:46:14 GMT</lastBuildDate><atom:link href="https://niebezpiecznik.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Niebezpiecznik]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[niebezpiecznik@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[niebezpiecznik@substack.com]]></itunes:email><itunes:name><![CDATA[Niebezpiecznik]]></itunes:name></itunes:owner><itunes:author><![CDATA[Niebezpiecznik]]></itunes:author><googleplay:owner><![CDATA[niebezpiecznik@substack.com]]></googleplay:owner><googleplay:email><![CDATA[niebezpiecznik@substack.com]]></googleplay:email><googleplay:author><![CDATA[Niebezpiecznik]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[CyberExpress #013 (04-06-2024)]]></title><description><![CDATA[W tym odcinku m.in. o pot&#281;&#380;nym wycieku danych z Santandera i Ticketmastera, &#322;amaniu 11 hase&#322;, podgl&#261;daniu u&#380;ytkownik&#243;w Windowsa i kilku wpadkach Google. Lektura zajmie Ci 4 minuty.]]></description><link>https://niebezpiecznik.substack.com/p/cyberexpress-013-04-06-2024</link><guid isPermaLink="false">https://niebezpiecznik.substack.com/p/cyberexpress-013-04-06-2024</guid><dc:creator><![CDATA[Niebezpiecznik]]></dc:creator><pubDate>Tue, 04 Jun 2024 12:44:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0yq1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe31f0ac-773b-4cc0-8140-cbce0d877971_600x400.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Na &#128008;&#8205;&#11035; 13 wydanie CyberExpressu przysz&#322;o Wam troch&#281; poczeka&#263;, ale gwarantujemy, &#380;e b&#281;dzie warto! Poza mi&#281;sistymi newsami, opisami narz&#281;dzi i technik, to wydanie ma te&#380; sponsora, a jest nim firma <strong>baramundi</strong>, wraz z kt&#243;r&#261;&nbsp;</p><blockquote><p>zapraszamy Was na <strong><a href="https://www.baramundi.com/pl-pl/easy-days/?utm_source=WERBUNG&amp;utm_medium=niebezpiecznik&amp;utm_campaign=Anzeige_easydays_05_2024_pl_PL">EASY DAYS</a>,</strong> czyli wydarzenie dla administrator&#243;w IT. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.baramundi.com/pl-pl/easy-days/?utm_source=WERBUNG&amp;utm_medium=niebezpiecznik&amp;utm_campaign=Anzeige_easydays_05_2024_pl_PL" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0yq1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe31f0ac-773b-4cc0-8140-cbce0d877971_600x400.png 424w, https://substackcdn.com/image/fetch/$s_!0yq1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe31f0ac-773b-4cc0-8140-cbce0d877971_600x400.png 848w, https://substackcdn.com/image/fetch/$s_!0yq1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe31f0ac-773b-4cc0-8140-cbce0d877971_600x400.png 1272w, https://substackcdn.com/image/fetch/$s_!0yq1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe31f0ac-773b-4cc0-8140-cbce0d877971_600x400.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0yq1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe31f0ac-773b-4cc0-8140-cbce0d877971_600x400.png" width="600" height="400" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/be31f0ac-773b-4cc0-8140-cbce0d877971_600x400.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:400,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:576555,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.baramundi.com/pl-pl/easy-days/?utm_source=WERBUNG&amp;utm_medium=niebezpiecznik&amp;utm_campaign=Anzeige_easydays_05_2024_pl_PL&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0yq1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe31f0ac-773b-4cc0-8140-cbce0d877971_600x400.png 424w, https://substackcdn.com/image/fetch/$s_!0yq1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe31f0ac-773b-4cc0-8140-cbce0d877971_600x400.png 848w, https://substackcdn.com/image/fetch/$s_!0yq1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe31f0ac-773b-4cc0-8140-cbce0d877971_600x400.png 1272w, https://substackcdn.com/image/fetch/$s_!0yq1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe31f0ac-773b-4cc0-8140-cbce0d877971_600x400.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></blockquote><p>Na Easy Days b&#281;dzie mo&#380;na: </p><ul><li><p>wzi&#261;&#263; udzia&#322; w praktycznych prezentacjach dotycz&#261;cych skutecznego <strong>zarz&#261;dzania punktami ko&#324;cowymi,</strong></p></li><li><p>uzyska&#263; odpowiedzi na nurtuj&#261;ce Was pytania np. <em><strong>w jaki spos&#243;b odpiera&#263; cyberataki?</strong></em> lub <em><strong>jak szybko i bez k&#322;opotu dokona&#263; migracji do Windows 11</strong></em>? </p></li><li><p>udoskonali&#263; sw&#243;j know-how, rozmawiaj&#261;c z ekspertami na temat optymalizacji swoich codziennych czynno&#347;ci </p></li></ul><p><strong>&#9200; KIEDY I GDZIE</strong> <br><strong>11 czerwca</strong> w warszawskiej Kinotece Multiplex od godziny <strong>13:30 do 17:30</strong></p><p><strong>&#128073; DARMOWA REJESTRACJA</strong><br>Aby si&#281;&nbsp;zapisa&#263;, <a href="https://www.baramundi.com/pl-pl/easy-days/?utm_source=WERBUNG&amp;utm_medium=niebezpiecznik&amp;utm_campaign=Anzeige_easydays_05_2024_pl_PL">przejd&#378;cie na t&#281; stron&#281;</a>. </p><div class="pullquote"><p>Jak zwykle, kiedy jest sponsor, to do CyberExpressu dorzucamy <strong>3 dodatkowe materia&#322;y premium</strong>, takie, kt&#243;rymi dzielimy si&#281; tylko z uczestnikami naszych p&#322;atnych szkole&#324;; takie, kt&#243;re przekazuj&#261; konkretn&#261;, praktyczn&#261; wiedz&#281;:</p><ol><li><p>&#346;wietny <a href="https://sparktoro.com/blog/an-anonymous-source-shared-thousands-of-leaked-google-search-api-documents-with-me-everyone-in-seo-should-see-them/">opis</a> tego, co Google uwzgl&#281;dnia przy pozycjonowaniu stron w wynikach vs to co twierdzi, &#380;e uwzgl&#281;dnia. Analiza by&#322;a mo&#380;liwa bo przypadkowo ujawniono wewn&#281;trzn&#261; dokumentacj&#281;&nbsp;Search API.    </p></li><li><p>Cudowny <a href="https://old.reddit.com/r/cybersecurity/comments/1cy9gmz/whats_the_worst_case_of_insider_threat_incidents/">w&#261;tek</a> o r&#243;&#380;nych &#8220;strasznych incydentach&#8221;. Mo&#380;na si&#281; wiele nauczy&#263;&#8230; czego nie robi&#263;. Albo pocieszy&#263;, &#380;e inni maj&#261;&nbsp;gorzej ;) </p></li><li><p>Szczeg&#243;&#322;owy i techniczny wywiad z thegrugq o &#8220;<a href="https://www.youtube.com/watch?v=3w7E4Hhtubw">osobistym OPSEC-u</a>&#8221;.</p></li></ol><p><strong>Fajne materia&#322;y? To w&#322;a&#347;nie dzi&#281;ki sponsorom &#128526; Je&#347;li Wasza firma te&#380; chcia&#322;aby pojawi&#263; si&#281;&nbsp;w naszym newsletterze i wspom&#243;c jego rozw&#243;j, to napiszcie do nas na cyberexpress@niebezpiecznik.pl </strong></p></div><p>A teraz, pora na linki!</p><h2>1. S&#261;d: policja mo&#380;e zmusza&#263; do odblokowania smartfona palcem</h2><p>Te smutne informacje pochodz&#261; z <a href="https://cdn.ca9.uscourts.gov/datastore/opinions/2024/04/17/22-50262.pdf">s&#261;dowego wyroku</a>, na razie w USA.  Pan Payne, zatrzymany w 2021 podczas kontroli drogowej, zosta&#322; oskar&#380;ony o handel substancjami, ekhm, mocno kontrolowanymi, a policjant, jeszcze na miejscu zdarzenia si&#322;&#261; u&#380;y&#322; kciuka Payne&#8217;a do odblokowania jego smartfona. Obro&#324;ca podnosi&#322; potem, &#380;e to nie by&#322;o OK, ale s&#261;d nie podzieli&#322;&nbsp;jego zdania. <br></p><p><code>&#128161; RADA: wy&#322;&#261;czcie sobie biometrie (albo tymczasowo j&#261; blokujcie) podczas &#8220;gor&#261;cych&#8221; sytuacji. Wtedy nikt silniejszy od Was nie odblokuje Wami Waszego smartfona. O ile nie podacie mu has&#322;a, a to ju&#380; zale&#380;y od Waszej odporno&#347;ci na kryptoanaliz&#281; gumow&#261; pa&#322;k&#261;&#8230;</code></p><div><hr></div><h2>2. Santader i Tickermaster ofiarami w&#322;amania do Snowflake</h2><p><a href="https://www.santander.com/en/stories/statement">Santander</a> i <a href="https://www.sec.gov/Archives/edgar/data/1335258/000133525824000081/lyv-20240520.htm">Ticketmaster</a> (w Polsce znane te&#380; jako LiveNation) zosta&#322;y zhackowane trac&#261;c dane, odpowiednio 30 milion&#243;w i 560 milion&#243;w klient&#243;w. Wyciek (1,3TB) zawiera informacje o rachunkach, numery kart p&#322;atniczych i oczywi&#347;cie dane osobowe. W&#322;amywacze (u&#380;ywaj&#261;cy nicka ShinyHunters, cho&#263; inni m&#243;wi&#261;, &#380;e to <strong>UNC5537</strong>) <a href="https://www.bleepingcomputer.com/news/security/snowflake-account-hacks-linked-to-santander-ticketmaster-breaches/">twierdzili</a>, &#380;e zhackowali pracownika Snowflake i wygenerowali tokeny, kt&#243;re da&#322;y im dost&#281;p do baz m.in. Santandera i Ticketmastera a niekt&#243;rzy sugeruj&#261; &#380;e ofiar&#261; pa&#347;&#263; mogli tak&#380;e inni u&#380;ytkownicy chmury Snowflake. Ale Snowflake <a href="https://community.snowflake.com/s/question/0D5VI00000Emyl00AB/detecting-and-preventing-unauthorized-user-access">zaprzecza</a> i podaje <a href="https://community.snowflake.com/s/article/Communication-ID-0108977-Additional-Information">IoC</a> po kt&#243;rych klienci mog&#261; sprawdzi&#263;, czy byli celem atak&#243;w. <br>  </p><p><code>&#128161; RADA: zweryfikujcie czy mo&#380;ecie na&#322;o&#380;y&#263; ACL-ki na dost&#281;py do paneli zewn&#281;trznych dostawc&#243;w. Gdzie to mo&#380;liwe aktywujcie te&#380; MFA. Wtedy atak na pracownika dostawcy us&#322;ugi niekoniecznie b&#281;dzie oznacza&#263; atak na Wasz&#261; instancj&#281;.</code></p><div><hr></div><h2>3. Baza 6 lat prywatno&#347;ciowych wpadek Google </h2><p>Baz&#281; dokumentuj&#261;c&#261; 6 lat wpadek Google zwi&#261;zanych z naruszeniami dotycz&#261;cymi prywatno&#347;ci <a href="https://www.androidauthority.com/google-leak-exposes-privacy-security-failures-3448323/">wykradziono</a> i udost&#281;pniono prasie. Przyk&#322;adowe incydenty to przypadkowe zachowanie pr&#243;bek g&#322;osu ~1000 dzieci czy ujawnianie przez Waze adres&#243;w u&#380;ytkownik&#243;w.  </p><p>Niekt&#243;rzy, te wpadki&nbsp;wykorzystaj&#261; do &#8220;hejtu&#8221; na Google, ale w rzeczywisto&#347;ci ta baza pokazuje, &#380;e firma troszczy si&#281; prywatno&#347;&#263;, zauwa&#380;a b&#322;&#281;dy i pr&#243;buje je naprawia&#263;. Ka&#380;dy podmiot (a zw&#322;aszcza takiej wielko&#347;ci i z tyloma us&#322;ugami) b&#281;dzie generowa&#263; incydenty dot. prywatno&#347;ci. Istotne jest to, jak na nie reaguje. A Google na nie reagowa&#322;o sprawnie i poprawnie.</p><div><hr></div><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-013-04-06-2024?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Nie wymagamy p&#322;acenia za czytanie <strong>CyberExpressu</strong> &#8212; jest darmowy. Dlatego b&#281;dzie nam bardzo mi&#322;o, je&#347;li <strong>udost&#281;pnisz linka tego newslettera znajomym</strong> z pracy np. na firmowym Slacku. Niech te&#380; stan&#261; si&#281; bezpieczniejsi!</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-013-04-06-2024?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://niebezpiecznik.substack.com/p/cyberexpress-013-04-06-2024?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><h2>4. Uwaga u&#380;ytkownicy Windows!</h2><p>Mo&#380;na wykra&#347;&#263; wszystko co robili&#347;cie na kompie. Oto  <a href="https://twitter.com/GossiTheDog/status/1796642426997649752">dwie linie kodu</a>, kt&#243;re nadu&#380;ywaj&#261; TEJ CHOREJ funkcji &#8220;Recall&#8221;, kt&#243;r&#261; wbudowano w Windows do screenshotowania (i OCR-owania) wszystkiego co u&#380;ytkownik wy&#347;wietli na ekranie. Prywatno&#347;ciowy koszmar.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-x8E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c91be25-b4c2-4352-80cd-e2ae72d7429e_500x590.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-x8E!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c91be25-b4c2-4352-80cd-e2ae72d7429e_500x590.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-x8E!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c91be25-b4c2-4352-80cd-e2ae72d7429e_500x590.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-x8E!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c91be25-b4c2-4352-80cd-e2ae72d7429e_500x590.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-x8E!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c91be25-b4c2-4352-80cd-e2ae72d7429e_500x590.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-x8E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c91be25-b4c2-4352-80cd-e2ae72d7429e_500x590.jpeg" width="500" height="590" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3c91be25-b4c2-4352-80cd-e2ae72d7429e_500x590.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:590,&quot;width&quot;:500,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78340,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-x8E!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c91be25-b4c2-4352-80cd-e2ae72d7429e_500x590.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-x8E!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c91be25-b4c2-4352-80cd-e2ae72d7429e_500x590.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-x8E!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c91be25-b4c2-4352-80cd-e2ae72d7429e_500x590.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-x8E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c91be25-b4c2-4352-80cd-e2ae72d7429e_500x590.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>5. By&#322;y minister zdrowia us&#322;ysza&#322; zarzuty</h2><p>Niedzielski <a href="https://www.rp.pl/przestepczosc/art40478801-byly-minister-zdrowia-adam-niedzielski-uslyszal-zarzut">ujawni&#322; publicznie</a>, jakie leki przyjmuje jeden z krytykuj&#261;cych ministerstwo lekarzy. Ta sprawa pokazuje, jak nieprawid&#322;owe jest wdro&#380;enie IKP (Internetowego Konta Pacjenta) i innych system&#243;w w Ministerstwie Zdrowia. Pacjenci powinni by&#263; powiadamiani o ka&#380;dym odczycie swoich danych, a w og&#243;le, to gdzie to mo&#380;liwe ich dane powinny by&#263; anonimizowane. </p><div class="poll-embed" data-attrs="{&quot;id&quot;:181444}" data-component-name="PollToDOM"></div><div><hr></div><h2>6. Historia z&#322;amania 11-letniego has&#322;a do portfela z 3 milionami USD</h2><p>Wired <a href="https://www.wired.com/story/roboform-password-3-million-dollar-crypto-wallet/">opisuje</a> jak uda&#322;o si&#281;&nbsp;wykorzysta&#263; luk&#281; w Roboform do odzyskania zapomnianego has&#322;a. Nagrod&#261; by&#322; dost&#281;p do portfela kryptowalutowego. A tu wyja&#347;nienie od &#322;&#261;mi&#261;cego w formie video:</p><div id="youtube2-o5IySpAkThg" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;o5IySpAkThg&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/o5IySpAkThg?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><h2>7. Wa&#380;ny wyrok dla Polak&#243;w</h2><p>Europejski Trybuna&#322; Praw Cz&#322;owieka <a href="https://panoptykon.org/wyrok-ETPC-inwigiliacja-2024">stwierdzi&#322;</a>, &#380;e &#8220;brak kontroli nad inwigilacj&#261; narusza prawa wszystkich Polek i Polak&#243;w &#8211; bez wzgl&#281;du na to, czym si&#281; zajmuj&#261; zawodowo.&#8221; Wyrok to wynik skargi m.in. Wojciecha Klickiego i Katarzyny Szymielewicz z Fundacji Panoptykon. Na marginesie, aktualnie kto&#347; Pegasusem <a href="https://citizenlab.ca/2024/05/pegasus-russian-belarusian-speaking-opposition-media-europe/">hackuje</a> mieszkaj&#261;cych w Polsce rosyjskich i bia&#322;oruskich opozycjonist&#243;w.</p><div><hr></div><h2>8. Google wycofuje si&#281;&nbsp;z wynik&#243;w od &#8220;AI&#8221;  </h2><p>Po fiasku i publicznym wy&#347;mianiu, firma <a href="https://www.nytimes.com/2024/06/01/technology/google-ai-overviews-rollback.html">zdecydowa&#322;a si&#281;&nbsp;</a>usun&#261;&#263; z wynik&#243;w odpowiedzi generowane przez AI. Przypomnijmy: internauci otrzymywali takie porady jak: stosuj klej podczas przyrz&#261;dzania pizzy albo jedz dwa kamienie dziennie. A potem, to ju&#380; internety podchwyci&#322;y &#347;mieszki i sie&#263; zosta&#322;a zalana dziesi&#261;tkami sfa&#322;szowanych screenshot&#243;w, kt&#243;re o&#347;miesza&#322;y googlowe AI. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PiM3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1597bdd1-abdc-4572-8046-9a9e438daf3d_1968x1116.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PiM3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1597bdd1-abdc-4572-8046-9a9e438daf3d_1968x1116.webp 424w, https://substackcdn.com/image/fetch/$s_!PiM3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1597bdd1-abdc-4572-8046-9a9e438daf3d_1968x1116.webp 848w, https://substackcdn.com/image/fetch/$s_!PiM3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1597bdd1-abdc-4572-8046-9a9e438daf3d_1968x1116.webp 1272w, https://substackcdn.com/image/fetch/$s_!PiM3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1597bdd1-abdc-4572-8046-9a9e438daf3d_1968x1116.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PiM3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1597bdd1-abdc-4572-8046-9a9e438daf3d_1968x1116.webp" width="1456" height="826" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1597bdd1-abdc-4572-8046-9a9e438daf3d_1968x1116.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:826,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Google's AI is now Encouraging People to commit Suicide | AINIRO.IO&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Google's AI is now Encouraging People to commit Suicide | AINIRO.IO" title="Google's AI is now Encouraging People to commit Suicide | AINIRO.IO" srcset="https://substackcdn.com/image/fetch/$s_!PiM3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1597bdd1-abdc-4572-8046-9a9e438daf3d_1968x1116.webp 424w, https://substackcdn.com/image/fetch/$s_!PiM3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1597bdd1-abdc-4572-8046-9a9e438daf3d_1968x1116.webp 848w, https://substackcdn.com/image/fetch/$s_!PiM3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1597bdd1-abdc-4572-8046-9a9e438daf3d_1968x1116.webp 1272w, https://substackcdn.com/image/fetch/$s_!PiM3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1597bdd1-abdc-4572-8046-9a9e438daf3d_1968x1116.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p><em>A teraz pora na co&#347; supertechnicznego:</em></p><h2>9. Od przypadkowego curla do odkrycia masowego hacka router&#243;w na ca&#322;ym &#347;wiecie</h2><p>Pan sobie spokojnie bada&#322; podatno&#347;&#263; XXE, kiedy zauwa&#380;y&#322;, &#380;e wysy&#322;ane przez niego requesty s&#261; &#8230;ponawiane przez 2 dziwne adresy IP. Kilka godzin analizy i trzy lata p&#243;&#378;niej, zagadka zosta&#322;a &#8220;rozwiazana&#8221;. D&#322;uga, ale bardzo <a href="https://samcurry.net/hacking-millions-of-modems">ciekawa lektura</a> ukazuj&#261;ca jak hakerzy hakowali haker&#243;w.</p><div><hr></div><h2>10. RCE w ChatGPT</h2><p>Oto <a href="https://x.com/marcofigueroa/status/1795758597730685270?s=12">kod Pythona</a>, kt&#243;ry wykona&#322;&nbsp;si&#281;&nbsp;po stronie ChataGPT.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Przeczyta&#322;e&#347; prawie ca&#322;y &#128642; <strong>CyberExpress</strong> Gratulacje! Je&#347;li nie otrzymujesz go na maila, to wpisz sw&#243;j adres poni&#380;ej, a zaczniesz go otrzymywa&#263; :-)</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2>== AUTOPROPAGANDA ==</h2><p>Czyli istotne tre&#347;ci, kt&#243;re opublikowali&#347;my na Niebezpieczniku od poprzedniego wydania newslettera: </p><ul><li><p><a href="https://niebezpiecznik.pl/post/jak-zwiekszyc-bezpieczenstwo-webaplikacji-dzieki-cloudflare/">Jak skonfigurowa&#263; darmow&#261; wersj&#281;&nbsp;Cloudflare do ochrony naszej strony?</a> </p><p></p></li></ul><blockquote><p><strong>&#9888;&#65039; Psst! Ten artuku&#322; pochodzi z cyklu pt. <a href="https://niebezpiecznik.pl/post/najczestsze-bledy-programistow-w-formularzu-resetu-hasla/#phw">Poradnik Hackera Webaplikacji </a>&#8212; w nim jeszcze wi&#281;cej wskaz&#243;wek dla os&#243;b zainteresowanych bezpiecze&#324;stwem serwis&#243;w internetowych.  </strong></p></blockquote><p></p><ul><li><p>Uruchomili&#347;my <a href="https://niebezpiecznik.pl/post/uruchamiamy-2-dniowe-praktyczne-szkolenie-z-osint-u/">dwudniow&#261; wersj&#281;&nbsp;naszego bestsellerowego szkolenia z OSINT-u</a>, gdzie uczymy jak pozyskiwa&#263; dane os&#243;b i firm z (nie zawsze) publicznie dost&#281;pnych &#378;r&#243;de&#322;. Na has&#322;o &#8220;CyberExpress&#8221; podczas rejestracji otrzymasz zni&#380;k&#281; (150 PLN). Wa&#380;ne do ko&#324;ca czerwca.  </p></li><li><p>Opisali&#347;my <a href="https://niebezpiecznik.pl/post/incydent-w-bnp-paribas-gsc-pokazal-spory-problem-z-systemem-zus/">incydent w BNP Paribas GSC</a>, kt&#243;ry ujawni&#322; problem z uprawnieniami na platformie ZUS &#8212; sprawd&#378;cie jak to jest u Was w firmach, bo pewnie tak samo &#378;le :)</p></li><li><p>Machn&#281;li&#347;my <a href="https://niebezpiecznik.pl/post/jak-atakowane-sa-polskie-firmy-posluchajcie-historii-tomasza/">superciekawy webinar z SoftwareMill</a> przedstawiaj&#261;cy kulisy wielopoziomowego ataku na ich firm&#281; oraz przypadkowych internaut&#243;w. </p></li><li><p>Przyjrzeli&#347;my si&#281;&nbsp;<a href="https://niebezpiecznik.pl/post/jak-rozpoznac-falszywa-agencje-zatrudnienia-pokazujemy-na-przykladzie/">scamowi na rekrutacj&#281; w Polsce</a> i usun&#281;li&#347;my z internetu jeden tego typu przybytek.</p></li><li><p>Obszernie opisali&#347;my atak na Medily, czyli kolejny <a href="https://niebezpiecznik.pl/post/dcg-centrum-medyczne-pokazuje-jak-nie-informowac-o-kradziezy-danych-pacjentow/">pot&#281;&#380;ny wyciek danych pacjent&#243;w</a>. Oraz to<a href="https://niebezpiecznik.pl/post/jak-wykradziono-dane-180-000-pacjentow-z-serwerow-firmy-medily/"> jak faktycznie dosz&#322;o do tego ataku</a>.</p></li><li><p>Przeanalizowali&#347;my propozycj&#281; nowego prawa, kt&#243;re ma walczy&#263; z hejtem i pokazali&#347;my <a href="https://niebezpiecznik.pl/post/chca-walczyc-z-hejtem-poprzez-wymog-logowania-adresow-ip/">dlaczego od strony technicznej to si&#281;&nbsp;nie uda</a>.</p></li><li><p>Pokazali&#347;my jak mo&#380;na by&#322;o <a href="https://niebezpiecznik.pl/post/pkob-bp-numery-dowodow-bot-infolinia/">pozyska&#263; numery dowod&#243;w klient&#243;w banku PKO BP</a> wyci&#261;gaj&#261;c je &#8230;od ich telefonicznego bota :)</p></li></ul><p></p><h2>== ZOBACZ SI&#280; Z NAMI ==</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://bilety.niebezpiecznik.pl" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gUWB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16d7a838-f91a-4efc-9bf6-5324fef4d33c_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!gUWB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16d7a838-f91a-4efc-9bf6-5324fef4d33c_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!gUWB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16d7a838-f91a-4efc-9bf6-5324fef4d33c_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!gUWB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16d7a838-f91a-4efc-9bf6-5324fef4d33c_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gUWB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16d7a838-f91a-4efc-9bf6-5324fef4d33c_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/16d7a838-f91a-4efc-9bf6-5324fef4d33c_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:&quot;https://bilety.niebezpiecznik.pl&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gUWB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16d7a838-f91a-4efc-9bf6-5324fef4d33c_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!gUWB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16d7a838-f91a-4efc-9bf6-5324fef4d33c_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!gUWB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16d7a838-f91a-4efc-9bf6-5324fef4d33c_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!gUWB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F16d7a838-f91a-4efc-9bf6-5324fef4d33c_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Wskrzesili&#347;my te&#380;&nbsp;nasz kultowy wyk&#322;ad &#8220;<a href="https://niebezpiecznik.pl/post/jak-nie-dac-sie-zhackowac-2024/">Jak nie da&#263; si&#281;&nbsp;zhackowa&#263;?</a>&#8221; &#8212; to 3,5h wszystkiego, co ka&#380;dy musi dzi&#347; wiedzie&#263; o cyberbezpiecze&#324;stwie. Jest humor, s&#261; pokazy atak&#243;w na &#380;ywo. A wszystko podane j&#281;zykiem, kt&#243;ry zrozumie ka&#380;dy (tak&#380;e Twoi rodzice i dziadkowie). Odwiedzimy:</p><ul><li><p><a href="https://nbzp.cz/jnsz-2406-wro">WROC&#321;AW, 20 czerwca 2024 -- kliknij tu aby si&#281; zapisa&#263;!</a></p></li><li><p><a href="https://nbzp.cz/jnsz-2406-lod">&#321;&#211;D&#377;, 21 czerwca 2024 -- kliknij tu aby si&#281; zapisa&#263;!</a></p></li><li><p><a href="https://nbzp.cz/jnsz-2406-kat">KATOWICE, 28 czerwca 2024 -- kliknij tu aby si&#281; zapisa&#263;!</a></p></li><li><p><a href="https://nbzp.cz/jnsz-kra-2410">KRAK&#211;W, 14 pa&#378;dziernika 2024 -- kliknij tu aby si&#281; zapisa&#263;!</a></p></li></ul><p>Ten wyk&#322;ad kierujemy przede wszystkim do os&#243;b prywatnych, ale je&#347;li chcesz, mo&#380;esz nas <strong>zaprosi&#263; do swojej firmy</strong> &#8212; wybierasz sobie wtedy jeden z kilku temat&#243;w, z kt&#243;rym do Was przyjedziemy &#8212; <a href="https://niebezpiecznik.pl/post/zapros-niebezpiecznika-do-swojej-firmy/">szczeg&#243;&#322;y akcji tutaj</a>.</p><h2>* * *</h2><p>Tym razem, zamiast memika na koniec, screen naszego najpopularniejszego Twitta z ostatniego miesi&#261;ca (w og&#243;le, to na Twitterze jeste&#347;my superaktywni, najaktywniejsi ze wszystkich naszych social medi&#243;w &#8212; <a href="https://twitter.com/niebezpiecznik">&#347;ledz nas tam, je&#347;li jeszcze tego nie robisz</a>) </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://x.com/niebezpiecznik/status/1793320380746064086" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!z-qf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdc0533e-120c-4d47-b388-838babf89506_1058x1930.png 424w, https://substackcdn.com/image/fetch/$s_!z-qf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdc0533e-120c-4d47-b388-838babf89506_1058x1930.png 848w, https://substackcdn.com/image/fetch/$s_!z-qf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdc0533e-120c-4d47-b388-838babf89506_1058x1930.png 1272w, https://substackcdn.com/image/fetch/$s_!z-qf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdc0533e-120c-4d47-b388-838babf89506_1058x1930.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!z-qf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdc0533e-120c-4d47-b388-838babf89506_1058x1930.png" width="1058" height="1930" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cdc0533e-120c-4d47-b388-838babf89506_1058x1930.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1930,&quot;width&quot;:1058,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2647124,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://x.com/niebezpiecznik/status/1793320380746064086&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!z-qf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdc0533e-120c-4d47-b388-838babf89506_1058x1930.png 424w, https://substackcdn.com/image/fetch/$s_!z-qf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdc0533e-120c-4d47-b388-838babf89506_1058x1930.png 848w, https://substackcdn.com/image/fetch/$s_!z-qf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdc0533e-120c-4d47-b388-838babf89506_1058x1930.png 1272w, https://substackcdn.com/image/fetch/$s_!z-qf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcdc0533e-120c-4d47-b388-838babf89506_1058x1930.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>Do nast&#281;pnego! Bezpieczno&#347;ci!</em></p>]]></content:encoded></item><item><title><![CDATA[CyberExpress #012 (29-01-2024)]]></title><description><![CDATA[W tym odcinku m.in. o setkach tysi&#281;cy zhackowanych TV z Androidem, g&#322;upotach wygadywanych przez szefa HP i tym, &#380;e durne algorytmy b&#281;d&#261; nas wsadza&#263; do wi&#281;zienia. Lektura zajmie Ci 3 minuty.]]></description><link>https://niebezpiecznik.substack.com/p/cyberexpress-012-29-01-2024</link><guid isPermaLink="false">https://niebezpiecznik.substack.com/p/cyberexpress-012-29-01-2024</guid><dc:creator><![CDATA[Piotr Konieczny 👾]]></dc:creator><pubDate>Mon, 29 Jan 2024 18:42:06 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/4ZPTjGG9t7s" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>To wydanie ma sponsora, a jest nim firma KRUK S.A.: </p><blockquote><p>W KRUKu dzi&#281;ki nowym technologiom u&#322;atwiamy klientom regulacje zobowi&#261;za&#324;. Automatyzacja i boty umo&#380;liwiaj&#261; szybsz&#261; obs&#322;ug&#281; i realizacj&#281; potrzeby uzyskania odpowiedzi na pytania &#8222;tu i teraz&#8221;. Klienci korzystaj&#261;cy z platform do sp&#322;at online zyskuj&#261; narz&#281;dzia do bezpiecznych transakcji i potwierdzenie, &#380;e informacje o zad&#322;u&#380;eniu otrzymuj&#261; z wiarygodnego &#378;r&#243;d&#322;a.</p></blockquote><p>Je&#347;li chcieliby&#347;cie pozna&#263; szczeg&#243;&#322;y, to d&#322;u&#380;szy tekst autorstwa ekspert&#243;w KRUKa na temat nowych technologii w bran&#380;y windykacji <a href="https://niebezpiecznik.pl/post/ile-mozna-zarobic-na-oszukaniu-800-polakow/">znajdziecie na Niebezpieczniku</a>. </p><div class="pullquote"><p>Jak zwykle, kiedy jest sponsor, to do CyberExpressu dorzucamy <strong>3 dodatkowe materia&#322;y premium</strong>, takie, kt&#243;rymi dzielimy si&#281; tylko z uczestnikami naszych p&#322;atnych szkole&#324;; takie, kt&#243;re przekazuj&#261; konkretn&#261;, praktyczn&#261; wiedz&#281;:</p><ol><li><p>Jak skonfigurowa&#263; <strong>atak phishingowy Browser in the Browser</strong> z u&#380;yciem Evilginx? <a href="https://www.youtube.com/watch?v=luJjxpEwVHI">Tutaj pe&#322;en opis, krok po kroku</a>.   </p></li><li><p>A jak <strong>ukry&#263; instancj&#281; phishingow&#261; przed namierzeniem</strong> i zdj&#281;ciem? <a href="https://www.jackphilipbutton.com/post/how-to-protect-evilginx-using-cloudflare-and-html-obfuscation">Tutaj kilka porad </a>dla RedTeamer&#243;w. </p></li><li><p>Jak zbudowa&#263; domowe laboratorium do tzw. Hardware Hackingu? <a href="https://voidstarsec.com/hw-hacking-lab/">Tu cenne wskaz&#243;wki</a>.</p></li></ol><p>Fajne materia&#322;y? To w&#322;a&#347;nie dzi&#281;ki sponsorom &#128526; Je&#347;li Wasza firma te&#380; chcia&#322;aby pojawi&#263; si&#281;&nbsp;w naszym newsletterze i wspom&#243;c jego rozw&#243;j, to napiszcie do nas na cyberexpress@niebezpiecznik.pl </p></div><p>A teraz, pora na linki!</p><h2>1. Algorytm do odzyskiwania &#8220;poci&#281;tych&#8221; pieni&#281;dzy</h2><p>Niesamowicie <a href="https://arxiv.org/abs/2401.06133">ciekawy opis</a> tego, jak mo&#380;na si&#281; wzbogaci&#263; skupuj&#261;c &#8220;wychodz&#261;c&#261; z obiegu walut&#281;&#8221;. W Hong Kongu za 100 dolar&#243;w sprzedaj&#261; w workach, jako pami&#261;tki, zniszczone banknoty. S&#261; poci&#281;te, ale warte 138 000 dolar&#243;w. Zgadnijcie, ile z nich da si&#281;&nbsp;odzyska&#263; u&#380;ywaj&#261;c odpowiedniej techniki&#8230;</p><div><hr></div><h2>2. Trafi&#322; do wi&#281;zienia przez b&#322;&#261;d systemu rozpoznawania twarzy</h2><p>Przera&#380;aj&#261;ca historia m&#281;&#380;czyzny, kt&#243;ry zosta&#322;&nbsp;zatrzymany po tym, jak system rozpoznawania twarzy uzna&#322;, &#380;e pasuje on do rysopisu rabusia. W wi&#281;zieniu wyrz&#261;dzono mu wiele nieprzyjemno&#347;ci. Teraz pozywa autora oprogramowania na 10 milion&#243;w dolar&#243;w.</p><p><a href="https://www.dailymail.co.uk/news/article-13007297/texas-man-sues-sunglass-hut-facial-recognition-wrongly-identified.html">LINK</a></p><div><hr></div><h2>3. Ataki na Jenkinsa!</h2><p>W sieci <a href="https://www.bleepingcomputer.com/news/security/exploits-released-for-critical-jenkins-rce-flaw-patch-now/">pojawi&#322;o si&#281;</a>&nbsp;sporo exploit&#243;w i s&#261; ju&#380; wykorzystywane do masowych atak&#243;w. Zapaczujcie swoje instancje. </p><div><hr></div><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-012-29-01-2024?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Nie wymagamy p&#322;acenia za czytanie CyberExpressu &#8212; jest darmowy. Dlatego b&#281;dzie nam bardzo mi&#322;o, je&#347;li udost&#281;pnisz linka tego newslettera znajomym z pracy np. na firmowym Slacku. Niech te&#380; stan&#261; si&#281; bezpieczniejsi!</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-012-29-01-2024?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://niebezpiecznik.substack.com/p/cyberexpress-012-29-01-2024?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><h2>4. Apple zmuszone przez Uni&#281; Europejsk&#261;</h2><p>&#8230;do obni&#380;enia op&#322;at dla programist&#243;w na terenie Europy. Co wi&#281;cej, Apple w og&#243;le mo&#380;e by&#263; pozbawione prowizji, je&#347;li tw&#243;rcy aplikacji opublikuj&#261; j&#261; poza oficjalnym sklepem i skorzystaj&#261; z alternatywnego po&#347;rednika w p&#322;atno&#347;ciach. Bo Unia Europejska wymusi&#322;a na Apple r&#243;wnie&#380; to, aby w Europie udost&#281;pniono u&#380;ytkownikom iOS mo&#380;liwo&#347;&#263; instalacji apek spoza sklepu. Od marca 2024.</p><ul><li><p><a href="https://developer.apple.com/support/storekit-external-entitlement-us/">Tu o&#347;wiadczenie Apple ws. nowych zasad</a></p></li><li><p><a href="https://www.facebook.com/piotrkonieczny/posts/pfbid0KCV7cTYgpKdoYsbZ9V6hpcddwW23M7vwRkWDK7Fq8YrY4SqWrhGeDhpmaj3HGJexl">A tu refleksje Piotrka i ciekawa dyskusja w komentarzach</a></p></li></ul><div><hr></div><h2>5. Po&#347;miejmy si&#281;&nbsp;z szefa HP</h2><p>Enrique Lores ostrzeg&#322; ludzi przed nieoficjalnymi tuszami. Straszy&#322;, &#380;e mog&#261; by&#263; &#8220;zawirusowane&#8221;, a ich u&#380;ycie w drukarce zainfekuje zar&#243;wno drukark&#281; jak i komputer. <a href="https://arstechnica.com/gadgets/2024/01/hp-ceo-blocking-third-party-ink-from-printers-fights-viruses/">Zobacz analiz&#281; tego, czy to w og&#243;le mo&#380;liwe</a>.</p><div><hr></div><h2>6. Powiadomienia na iPhonach s&#261; u&#380;ywane do &#347;ledzenia u&#380;ytkownik&#243;w </h2><p>Okazuje si&#281;, &#380;e niekt&#243;re z aplikacji (nawet je&#347;li nie s&#261; uruchomione) to wysy&#322;aj&#261; powiadomienia na iPhony tylko po to, aby przy okazji zebra&#263; kilka cennych informacji na temat urz&#261;dzenia. Potem wykorzystuj&#261; te dane do &#347;ledzenia u&#380;ytkownik&#243;w. <a href="https://twitter.com/mysk_co/status/1750502700112916504">Tu opis tekstowy</a> a poni&#380;ej demo &#8220;ataku&#8221; na YT:</p><div id="youtube2-4ZPTjGG9t7s" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;4ZPTjGG9t7s&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/4ZPTjGG9t7s?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><h2>7. Microsoft zhackowany przez GRU</h2><p>Ciekawa i szczeg&#243;&#322;owa analiza ataku <a href="https://www.microsoft.com/en-us/security/blog/2024/01/25/midnight-blizzard-guidance-for-responders-on-nation-state-attack/">opublikowana</a> przez Microsoft. TL;DR: zacz&#281;&#322;o si&#281;&nbsp;od serwera testowego, kt&#243;ry nie mia&#322; MFA i mia&#322;&nbsp;s&#322;abe has&#322;o. I tu jest moment kiedy mo&#380;ecie zrobi&#263; &#129318;&#8205;&#9794;&#65039;. Has&#322;o odkryto zwyk&#322;ym <em>password sprayingiem</em> ale realizowanym przez IP z dobr&#261; reputacj&#261;. Potem by&#322;o ju&#380;&nbsp;tylko ciekawiej.</p><div><hr></div><h2>8. Odtajnione listy ujawniaj&#261; warsztat NSA  </h2><p>Obszerny opis tego, jak NSA zdobywa informacje od broker&#243;w danych i wykorzystuje je do prowadzenia swoich operacji.<br><br><a href="https://www.wyden.senate.gov/imo/media/doc/signed_wyden_letter_to_dni_re_nsa_purchase_of_domestic_metadata_and_ftc_order_on_data_brokers_with_attachments.pdf">LINK</a></p><div><hr></div><p><em>A teraz pora na co&#347; supertechnicznego:</em></p><h2>9. Tworzenia ROM-u GameBoy&#8217;a &#8230;z audio(crasha)</h2><p>M&#243;wi&#261;c najpro&#347;ciej, ten kosmita odtworzy&#322; ca&#322;&#261;&nbsp;gr&#281; na podstawie wielu crashy, a dok&#322;adniej, d&#378;wi&#281;k&#243;w w tych crashach &#129327;</p><div id="youtube2-0-7PSmYYHF0" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;0-7PSmYYHF0&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/0-7PSmYYHF0?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><h2>10. Setki tysi&#281;cy telewizor&#243;w u&#380;yto do ataku</h2><p>Zainfekowano 170 000 telewizor&#243;w (AndroidTV). Botnet wykorzystywano do atak&#243;w, m.in. DDoS, ale r&#243;wnie&#380; do wy&#347;wietlania tre&#347;ci propagandowych. <br><br><a href="https://www.theregister.com/2024/01/18/bigpanzi_botnet_smart_tvs/">LINK</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Przeczyta&#322;e&#347; prawie ca&#322;y &#128642; CyberExpress (newsletter Niebezpiecznika)! Gratulacje! Je&#347;li nie otrzymujesz go na maila, to wpisz sw&#243;j adres poni&#380;ej, a zaczniesz go otrzymywa&#263; :-)</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>== AUTOPROPAGANDA ==</h2><p>Czyli istotne tre&#347;ci z Niebezpiecznika od poprzedniego wydania newslettera: </p><ul><li><p>Programujecie lub testujecie aplikacje webowe? To zobaczcie nasz nowy cykl o <strong>bezpiecze&#324;stwie webaplikacji</strong>, w ramach kt&#243;rego opublikowali&#347;my ju&#380; 2 techniczne artyku&#322;y: </p><ul><li><p><a href="https://niebezpiecznik.pl/post/przydatne-rozszerzenia-do-przegladarek-idealne-dla-programistow-lub-pentesterow/">TOP5 dodatk&#243;w do przegl&#261;darek</a> pomocnych w pracy programisty lub pentestera webaplikacji</p></li><li><p><a href="https://niebezpiecznik.pl/post/najczestsze-bledy-programistow-w-formularzu-resetu-hasla/">Jak wykorzysta&#263; formularz przypominania hase&#322; do zhackowania webaplikacji?</a> <br><br></p></li></ul></li></ul><blockquote><p><strong>&#9888;&#65039; Nie zapomnijcie zapisa&#263; si&#281; do dedykowanego temu cyklowi newslettera pt. <a href="https://niebezpiecznik.pl/post/najczestsze-bledy-programistow-w-formularzu-resetu-hasla/#phw">Poradnik Hackera Webaplikacji </a>&#8212; w nim jeszcze wi&#281;cej wskaz&#243;wek dla os&#243;b zainteresowanych bezpiecze&#324;stwem serwis&#243;w internetowych </strong></p></blockquote><p></p><ul><li><p>Zn&#243;w mo&#380;na wzi&#261;&#263; darmowy udzia&#322;&nbsp;w naszych szkoleniach w ramach KFS. <a href="https://niebezpiecznik.pl/post/wez-udzial-w-naszych-szkoleniach-za-darmo-2/">Szczeg&#243;&#322;y tutaj</a>. </p></li><li><p>Ciekawy <a href="https://niebezpiecznik.pl/post/ransomware-moze-zaatakowac-wkretarki-bosh-rexroth/">atak na wkr&#281;tarki Bosch</a>, czyli o &#8220;internecie rzeczy&#8221; i braku bezpiecze&#324;stwa.</p></li><li><p>Podsumowanie nowych informacji na temat <a href="https://niebezpiecznik.pl/post/dane-z-alab-znow-w-darknecie-uporzadkowane-numerami-pesel/">wycieku z ALAB</a></p></li><li><p>O <a href="https://niebezpiecznik.pl/post/ktos-zawiesza-smartfony-w-warszawskim-metrze/">atakach w warszawskim metrze</a> (i nie tylko tam), kt&#243;re zawieszaj&#261; smartfony.</p></li><li><p>O 3 sposobach dla rodzic&#243;w na <a href="https://niebezpiecznik.pl/post/jak-namierzyc-lokalizacje-swojego-dziecka/">namierzanie lokalizacji swojego dziecka</a></p></li><li><p>O <a href="https://niebezpiecznik.pl/post/istotne-zmiany-w-aplikacji-mobilnej-ing/">zmianach w aplikacji mobilnej ING</a> </p></li><li><p>I o tym,<a href="https://niebezpiecznik.pl/post/donald-tusk-kod-blokady-telefonu/"> jakiego kodu Donald Tusk u&#380;ywa do odblokowania smartfonu</a>. </p></li></ul><h2>* * *</h2><p>I to tyle na dzi&#347;. Na koniec nie jeden obrazek, a kilka &#8212; wszystkie b&#281;d&#261;ce gratk&#261; dla historyk&#243;w komputer&#243;w. Wielka Brytania &#347;wi&#281;tuje 80 lat Colossusa, czyli komputera, kt&#243;ry zosta&#322; wykorzystany do &#322;amania szyfr&#243;w w czasie II wojny &#347;wiatowej. Z tego tytu&#322;u opublikowano <a href="https://www.gchq.gov.uk/news/colossus-80">kilka odtajnionych fotek</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-VNQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2540bc7-3099-4de9-a704-d2a20519a00c_1442x1202.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-VNQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2540bc7-3099-4de9-a704-d2a20519a00c_1442x1202.png 424w, https://substackcdn.com/image/fetch/$s_!-VNQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2540bc7-3099-4de9-a704-d2a20519a00c_1442x1202.png 848w, https://substackcdn.com/image/fetch/$s_!-VNQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2540bc7-3099-4de9-a704-d2a20519a00c_1442x1202.png 1272w, https://substackcdn.com/image/fetch/$s_!-VNQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2540bc7-3099-4de9-a704-d2a20519a00c_1442x1202.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-VNQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2540bc7-3099-4de9-a704-d2a20519a00c_1442x1202.png" width="1442" height="1202" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d2540bc7-3099-4de9-a704-d2a20519a00c_1442x1202.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1202,&quot;width&quot;:1442,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:933071,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-VNQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2540bc7-3099-4de9-a704-d2a20519a00c_1442x1202.png 424w, https://substackcdn.com/image/fetch/$s_!-VNQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2540bc7-3099-4de9-a704-d2a20519a00c_1442x1202.png 848w, https://substackcdn.com/image/fetch/$s_!-VNQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2540bc7-3099-4de9-a704-d2a20519a00c_1442x1202.png 1272w, https://substackcdn.com/image/fetch/$s_!-VNQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2540bc7-3099-4de9-a704-d2a20519a00c_1442x1202.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><br><em>Do nast&#281;pnego!</em></p>]]></content:encoded></item><item><title><![CDATA[CyberExpress #011 (11-10-2023)]]></title><description><![CDATA[W tym odcinku o: rekordowym ataku DDoS, wycieku gen&#243;w, policjantach, kt&#243;rzy woleli gra&#263; ni&#380; pomaga&#263; i tym jak wykorzysta&#263; wzrok ChataGPT. Lektura zajmie Ci 3 minuty.]]></description><link>https://niebezpiecznik.substack.com/p/cyberexpress-011-11-10-2023</link><guid isPermaLink="false">https://niebezpiecznik.substack.com/p/cyberexpress-011-11-10-2023</guid><pubDate>Wed, 11 Oct 2023 16:01:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acf44c9-f804-494b-990d-5e9f8faf2eea_1290x1329.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>To wydanie nie ma sponsora, wi&#281;c od razu przechodzimy do link&#243;w</p><h2>1. Genetyczny wyciek</h2><p>Z serwisu 23andMe przetwarzaj&#261;cego DNA wyciek&#322;y setki terabajt&#243;w (!) danych u&#380;ytkownik&#243;w, w tym ich fenotypy, zdj&#281;cia, dane identyfikacyjne oraz informacje o zdrowiu. Serwis utrzymuje, &#380;e powodem by&#322;o u&#380;ycie przez ofiary tego samego has&#322;a co do innych miejsc. Co ciekawe, poszkodowani s&#261; tak&#380;e ci, na kt&#243;rych konta si&#281; nie w&#322;amano, a winna jest us&#322;uga &#8220;DNA Relatives&#8221;. Dzi&#281;ki niej dane "nie-ofiar&#8221; by&#322;y mo&#380;liwe do pobrania z kont, kt&#243;re przej&#281;to, bo nie-ofiara i ofiara by&#322;y genetycznie &#8220;spokrewnione&#8221;. Po raz pierwszy dane wystawiono na sprzeda&#380;&nbsp;2 miesi&#261;ce temu. Serwis 23andMe jest krytykowany za woln&#261; reakcj&#281;. <br><a href="https://arstechnica.com/security/2023/10/private-23andme-user-data-is-up-for-sale-after-online-scraping-spree/">LINK</a></p><h2>2. Opis nowego typu DDoSa (HTTP/2 Rapid Reset)</h2><p>Google zdradzi&#322;o, &#380;e przyj&#281;&#322;o na klat&#281; 398 milion&#243;w request&#243;w na sekund&#281; i porz&#261;dnie opisa&#322;o na czym polega podatno&#347;&#263;&nbsp;w HTTP/2 wykorzystana do ataku.<br><a href="https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack">LINK</a></p><div><hr></div><h2>3. Dziura w popularnym D-Linku</h2><p><a href="https://www.bleepingcomputer.com/news/security/d-link-wifi-range-extender-vulnerable-to-command-injection-attacks/">LINK</a></p><p>&#8230;i przy okazji &#322;ami&#261;cy serce obrazek od znalazcy innego b&#322;&#281;du w D-Linku:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!A7TZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc83a91-6e3c-4389-83bd-1fa941a1f56b_1199x493.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!A7TZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc83a91-6e3c-4389-83bd-1fa941a1f56b_1199x493.jpeg 424w, https://substackcdn.com/image/fetch/$s_!A7TZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc83a91-6e3c-4389-83bd-1fa941a1f56b_1199x493.jpeg 848w, https://substackcdn.com/image/fetch/$s_!A7TZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc83a91-6e3c-4389-83bd-1fa941a1f56b_1199x493.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!A7TZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc83a91-6e3c-4389-83bd-1fa941a1f56b_1199x493.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!A7TZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc83a91-6e3c-4389-83bd-1fa941a1f56b_1199x493.jpeg" width="1199" height="493" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5bc83a91-6e3c-4389-83bd-1fa941a1f56b_1199x493.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:493,&quot;width&quot;:1199,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="https://substackcdn.com/image/fetch/$s_!A7TZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc83a91-6e3c-4389-83bd-1fa941a1f56b_1199x493.jpeg 424w, https://substackcdn.com/image/fetch/$s_!A7TZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc83a91-6e3c-4389-83bd-1fa941a1f56b_1199x493.jpeg 848w, https://substackcdn.com/image/fetch/$s_!A7TZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc83a91-6e3c-4389-83bd-1fa941a1f56b_1199x493.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!A7TZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5bc83a91-6e3c-4389-83bd-1fa941a1f56b_1199x493.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>4. Atak (?) na gazoci&#261;g Balticconnector</h2><p>Finlandia uwa&#380;a, &#380;e kto&#347; zniszczy&#322; gazoci&#261;g &#322;&#261;cz&#261;cy j&#261; z Estoni&#261;. By&#322;y teorie o wybuchach, ale aktualnie przewa&#380;a &#8220;u&#380;ycie zewn&#281;trznej si&#322;y bocznej&#8221;. Co mo&#380;e sugerowa&#263; zerwanie kotwic&#261;. Nieopodal mia&#322; by&#263; zakotwiczony rosyjski statek. &#346;wietny w&#261;tek pokazuj&#261;cy rozw&#243;j wydarze&#324; na bie&#380;&#261;co <a href="https://nafo.uk/@hanse_mina/111210417846358533">tutaj</a>.</p><div><hr></div><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-011-11-10-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Nie musisz p&#322;aci&#263; za czytanie CyberExpressu, ale b&#281;dzie nam bardzo mi&#322;o, je&#347;li udost&#281;pnisz linka tego newslettera znajomym z pracy np. na firmowym Slacku. Niech te&#380; stan&#261; si&#281; bezpieczniejsi!</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-011-11-10-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://niebezpiecznik.substack.com/p/cyberexpress-011-11-10-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><h2>5. Podatno&#347;&#263; w curl  </h2><p>&#321;atajcie, wsz&#281;dzie gdzie macie. A jako zale&#380;no&#347;&#263; macie pewnie w wielu miejscach o kt&#243;rych nawet nie zdajecie sobie sprawy... <br><a href="https://curl.se/docs/security.html">LINK</a></p><div><hr></div><h2>6. &#321;atajcie te&#380; &#8230;Wordpada  </h2><p>Dziura pozwala na kradzie&#380; hashy NTLM.<br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36563">LINK</a></p><div><hr></div><h2>7. Uprawnienia w Azure</h2><p>U&#380;yteczny serwis dla chmurowych sysadmin&#243;w &#8230;i haker&#243;w ;)<br><a href="https://azure.permissions.cloud/">LINK</a></p><div><hr></div><h2>8. Ile &#322;amie si&#281;&nbsp;has&#322;o do zipa b&#281;d&#261;ce numerem telefonu?</h2><p>Tomek dosta&#322; e-maila do innego Tomka. Z za&#322;&#261;cznikiem zaszyfrowanym numerem telefonu tamtego Tomka. No wi&#281;c z&#322;ama&#322; je w 3 sekundy.<br><a href="https://www.facebook.com/informatykzakladowy/posts/pfbid0TmDiU4SmPvPRwEzbT2ywEvwDCZEZvP1JRb1HyxDM3EZeuhg6gd8ZaanE9uPTc2T7l">LINK</a></p><div><hr></div><h2>9. Policjanci zignorowali wezwanie bo grali w pokemony </h2><p>I jest to na video&#8230;<br><a href="https://www.404media.co/video-reveals-crucial-details-of-lapd-ignoring-robbery-to-catch-togetic-in-pokemon-go/">LINK</a></p><div><hr></div><h2>10. zastosowa&#324; ChatGPT-Vision </h2><p>I na koniec prawdziwa pere&#322;ka. Jak mo&#380;na wykorzysta&#263; to, &#380;e ChatGPT dosta&#322; &#8220;wzrok&#8221;? Mo&#380;na np. kaza&#263;&nbsp;mu odcenzurowa&#263; dokumenty, zakodowa&#263; co&#347; na podstawie pliku z Figmy, czy pokaza&#263; zdj&#281;cie uszkodzenia w samochodzie i otrzyma&#263; informacje o wymaganych krokach naprawy. Mo&#380;na te&#380;&nbsp;poprosi&#263; o wskazanie tego, w co si&#281; ubra&#263;, &#380;eby pasowa&#322;o do siebie. I wiele innych.<br><a href="https://twitter.com/_borriss_/status/1711757787212947896?s=12">LINK</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Przeczyta&#322;e&#347; prawie ca&#322;y &#128642; CyberExpress (newsletter Niebezpiecznika)! Gratulacje! Je&#347;li nie otrzymujesz go na maila, to wpisz sw&#243;j adres poni&#380;ej, a zaczniesz go otrzymywa&#263; :-)</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>== AUTOPROPAGANDA ==</h2><p>Istotne tre&#347;ci z Niebezpiecznika z minionych dni: </p><ul><li><p><a href="https://niebezpiecznik.pl/post/cyberberbezpieczny-samorzad-zaaplikuj-i-wez-udzial-w-naszych-szkoleniach-za-darmo/">Darmowe szkolenia dla urz&#281;dnik&#243;w</a>.  Niebawem ko&#324;czy si&#281; czas na zg&#322;oszenie, wi&#281;c je&#347;li pracujecie w urz&#281;dzie, nie przegapcie! </p></li><li><p>Przekrojowa analiza pierwszych dni konfliktu Izraelsko-Palesty&#324;skiego ale <a href="https://niebezpiecznik.pl/post/jak-wyglada-konflikt-izraelsko-palestynski-w-cyberprzestrzeni/">tylko w obszarze cyberprzestrzeni</a>.</p></li><li><p>Ciekawy <a href="https://niebezpiecznik.pl/post/wyborczy-piraci-zagluszyli-radio-i-obrazili-kandydatke-do-sejmu/">atak radiowy</a>, czyli o tym jak kto&#347; od 2 tygodni w Kielcach zag&#322;usza radio VOX FM aby obra&#380;a&#263; jedn&#261;&nbsp;z kandydatek do sejmu. </p></li></ul><h2>* * *</h2><p>I to tyle na dzi&#347;. Jeszcze tylko &#347;mieszny obrazek i ko&#324;czymy:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BBBM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acf44c9-f804-494b-990d-5e9f8faf2eea_1290x1329.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BBBM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acf44c9-f804-494b-990d-5e9f8faf2eea_1290x1329.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BBBM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acf44c9-f804-494b-990d-5e9f8faf2eea_1290x1329.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BBBM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acf44c9-f804-494b-990d-5e9f8faf2eea_1290x1329.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BBBM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acf44c9-f804-494b-990d-5e9f8faf2eea_1290x1329.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BBBM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acf44c9-f804-494b-990d-5e9f8faf2eea_1290x1329.jpeg" width="1290" height="1329" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7acf44c9-f804-494b-990d-5e9f8faf2eea_1290x1329.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1329,&quot;width&quot;:1290,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:181555,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BBBM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acf44c9-f804-494b-990d-5e9f8faf2eea_1290x1329.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BBBM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acf44c9-f804-494b-990d-5e9f8faf2eea_1290x1329.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BBBM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acf44c9-f804-494b-990d-5e9f8faf2eea_1290x1329.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BBBM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7acf44c9-f804-494b-990d-5e9f8faf2eea_1290x1329.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><br><em>Do nast&#281;pnego!</em></p>]]></content:encoded></item><item><title><![CDATA[CyberExpress #010 (06-10-2023)]]></title><description><![CDATA[Lektura tego wydania zajmie ci 4 minuty, w trakcie kt&#243;rych poznasz 20 ciekawych materia&#322;&#243;w (news&#243;w, poradnik&#243;w, analiz i narz&#281;dzi) zwi&#261;zanych z cyberbezpiecze&#324;stwem.]]></description><link>https://niebezpiecznik.substack.com/p/cyberexpress-010</link><guid isPermaLink="false">https://niebezpiecznik.substack.com/p/cyberexpress-010</guid><dc:creator><![CDATA[Piotr Konieczny 👾]]></dc:creator><pubDate>Fri, 06 Oct 2023 12:40:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!UWi3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8de95b-49d9-4225-be13-a79259059414_1852x1252.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Wracamy po wakacjach do regularnego CyberExpressowania! Czy t&#281;sknili&#347;cie za nami cho&#263; troch&#281;? ;) </p><p>Poni&#380;ej, jak zwykle znajdziecie najwa&#380;niejsze wydarzenia ze &#347;wiata cyberbezpiecze&#324;stwa z ostatnich godzin, ale wcze&#347;niej &#8230;zagadka od sponsora tego odcinka &#8212; <a href="https://www.idc.com/eu/events/71057-idc-cloud-security?_gl=1*1d4agpn*_gcl_au*MTA4NTgxODExMS4xNjkyNzg0NjM5*_ga*MTUyNzM3OTMyLjE2MzM1OTk4MzY.*_ga_541ENG1F9X*MTY5NjMyNDY4MS4yMjkuMS4xNjk2MzI2MzY0LjU0LjAuMA..">konferencji IDC Cloud &amp; Security</a> &#8212; <strong>ile twarzy rozpoznajecie na poni&#380;szej fotce?</strong> I dodatkowe pytanie od nas: ile odcink&#243;w naszego podcastu &#8220;<a href="https://open.spotify.com/show/5MxNt9v6eCH4xxSFqRY1oS">Na Pods&#322;uchu</a>&#8221; to rozmowy z kim&#347; z poni&#380;szej fotki? </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://www.idc.com/eu/events/71057-idc-cloud-security?_gl=1*1d4agpn*_gcl_au*MTA4NTgxODExMS4xNjkyNzg0NjM5*_ga*MTUyNzM3OTMyLjE2MzM1OTk4MzY.*_ga_541ENG1F9X*MTY5NjMyNDY4MS4yMjkuMS4xNjk2MzI2MzY0LjU0LjAuMA.." data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9snX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931d525b-3094-4e6a-aa89-347eb57ff206_900x200.png 424w, https://substackcdn.com/image/fetch/$s_!9snX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931d525b-3094-4e6a-aa89-347eb57ff206_900x200.png 848w, https://substackcdn.com/image/fetch/$s_!9snX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931d525b-3094-4e6a-aa89-347eb57ff206_900x200.png 1272w, https://substackcdn.com/image/fetch/$s_!9snX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931d525b-3094-4e6a-aa89-347eb57ff206_900x200.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9snX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931d525b-3094-4e6a-aa89-347eb57ff206_900x200.png" width="900" height="200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/931d525b-3094-4e6a-aa89-347eb57ff206_900x200.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:200,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:223670,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.idc.com/eu/events/71057-idc-cloud-security?_gl=1*1d4agpn*_gcl_au*MTA4NTgxODExMS4xNjkyNzg0NjM5*_ga*MTUyNzM3OTMyLjE2MzM1OTk4MzY.*_ga_541ENG1F9X*MTY5NjMyNDY4MS4yMjkuMS4xNjk2MzI2MzY0LjU0LjAuMA..&quot;,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9snX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931d525b-3094-4e6a-aa89-347eb57ff206_900x200.png 424w, https://substackcdn.com/image/fetch/$s_!9snX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931d525b-3094-4e6a-aa89-347eb57ff206_900x200.png 848w, https://substackcdn.com/image/fetch/$s_!9snX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931d525b-3094-4e6a-aa89-347eb57ff206_900x200.png 1272w, https://substackcdn.com/image/fetch/$s_!9snX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F931d525b-3094-4e6a-aa89-347eb57ff206_900x200.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Odpowiedzi na pytania wpisujcie w komentarzach na Substacku pod tym wydaniem CyberExpressu. Pierwszym 3 osobom kt&#243;re poprawnie zdeanonimizuj&#261;&nbsp;wszystkie twarze oraz wska&#380;&#261; numery odcink&#243;w podcastu, wy&#347;lemy nasz <a href="https://koszyk.niebezpiecznik.pl/cyber-kubek">cyber-kubek</a>. A teraz pora na wiadomo&#347;&#263; od sponsora:</p><blockquote><p>Ju&#380; <strong>26 pa&#378;dziernika w Hotelu Nobu w Warszawie</strong> IDC Polska organizuje<strong> </strong>kolejn&#261; edycj&#281; konferencji IDC Cloud &amp; Security. W programie praktyczne case studies, wymiana do&#347;wiadcze&#324; w gronie CIO i CISO, a przede wszystkim znakomici prelegenci. Porozmawiamy&nbsp;m.in. o mapie zagro&#380;e&#324;, nowej roli CISO, bezpiecze&#324;stwie chmury i aplikacji, wymogach regulacyjnych, roli  reskillingu, sztucznej inteligencji, a nawet cyberbezpiecze&#324;stwie w kosmosie.</p></blockquote><p>U&#380;yjcie <strong><a href="https://ceeevents.idc.com/event/f1eab369-15c5-4e6f-a468-57fa08318a65/regProcessStep1?_gl=1*12izhlk*_ga*MTUyNzM3OTMyLjE2MzM1OTk4MzY.*_ga_541ENG1F9X*MTY5NjMzMjYxMS4yMzEuMC4xNjk2MzMyNjExLjYwLjAuMA..">podczas rejestracji</a></strong> kodu <strong>NIEBEZPIECZNIK, </strong>to otrzymacie <strong>30% rabatu na bilet</strong>. </p><div class="pullquote"><p>Dzi&#281;ki sponsorowi to wydanie CyberExpressu zawiera <strong>dwa dodatkowe materia&#322;y premium</strong>, takie, kt&#243;rymi dzielimy si&#281; tylko z uczestnikami naszych p&#322;atnych szkole&#324;; takie, kt&#243;re przekazuj&#261; konkretn&#261;, praktyczn&#261; wiedz&#281;:</p><ol><li><p><a href="https://atomicredteam.io/atomic-red-team/">Atomic Red Team </a>czyli zestaw test&#243;w, kt&#243;rymi mo&#380;ecie symulowa&#263; r&#243;&#380;ne ataki. Wszystko <a href="https://docs.google.com/spreadsheets/d/1YAK27jpd7j1xveWg80M56JUgJdx3xcN9K8PF02LOejs/edit#gid=1271696862">cudnie zmapowane </a>na MITRE ATT&amp;CK. Prawdziwe z&#322;oto. A do tego za darmo!  </p></li><li><p><a href="https://github.com/yeswehack/vulnerable-code-snippets">Dziurawy kod</a> &#8212; pot&#281;&#380;ny zbi&#243;r fragment&#243;w kodu z podatno&#347;ciami. Idealne do nauki, czego nie robi&#263; (i jak szuka&#263; b&#322;&#281;d&#243;w)!</p></li></ol><p>Fajne linki? To podzi&#281;kujcie sponsorowi <a href="https://www.idc.com/eu/events/71057-idc-cloud-security?_gl=1*1d4agpn*_gcl_au*MTA4NTgxODExMS4xNjkyNzg0NjM5*_ga*MTUyNzM3OTMyLjE2MzM1OTk4MzY.*_ga_541ENG1F9X*MTY5NjMyNDY4MS4yMjkuMS4xNjk2MzI2MzY0LjU0LjAuMA..">klikaj&#261;c tutaj</a> &#128526;</p></div><p>Je&#347;li Wasza firma te&#380; chcia&#322;aby pojawi&#263; si&#281;&nbsp;w sekcji sponsorskiej i wspom&#243;c rozw&#243;j tego newslettera, napiszcie do nas na <em>cyberexpress@niebezpiecznik.pl</em></p><p>A teraz, pora na linki!</p><h2>1. Regu&#322;y dla haker&#243;w od Czerwonego Krzy&#380;a</h2><p>Natychmiast po <a href="https://blogs.icrc.org/law-and-policy/2023/10/04/8-rules-civilian-hackers-war-4-obligations-states-restrain-them/">opublikowaniu</a> wszyscy jednog&#322;o&#347;nie je wy&#347;miali :) A proukrai&#324;scy hakerzy <a href="http://web.archive.org/web/20231004195529/https://redcross.ru/">zhackowali</a> nawet w zwi&#261;zku z tym rosyjsk&#261; stron&#281; Czerwonego Krzy&#380;a i o&#347;wiadczyli, &#380;e &#8220;<em>we will use every opportunity to cause the most harm to our enemy using any means available&#8221;.</em></p><p>Pod koniec 2022 <a href="https://niebezpiecznik.pl/post/czerwony-krzyz-chce-oznaczac-strony-szpitali-zeby-cyberprzestepcy-ich-nie-atakowali/">informowali&#347;my</a>, &#380;e Czerwony Krzy&#380; chcia&#322; oznacza&#263; specjaln&#261; &#8220;cyfrow&#261; plakietk&#261;&#8221; strony instytucji, kt&#243;re nie powinny by&#263; atakowane w cyberprzestrzeni, np. szpitali. Z tego pomys&#322;u te&#380; szydzono.</p><div><hr></div><h2>2. Z&#322;amiesz te 5 hashy?</h2><p>To dostaniesz <strong>~50 000 z&#322;otych</strong> lub trzy razy tyle, je&#347;li kwota zostanie przeznaczona na cele charytatywne.<br><a href="https://words.filippo.io/dispatches/seeds-bounty/">LINK</a></p><div><hr></div><h2>3. Czy to deepfake? </h2><p>Niesamowita historia sprawy s&#261;dowej o deepfake&#8217;a, kt&#243;ry &#8230;okaza&#322; si&#281; nie by&#263; deepfakem. Skompromitowana bohaterka nagrania zd&#261;&#380;y&#322;a&nbsp;objecha&#263; wszystkie media jako &#8220;ofiara deepfake&#8217;a&#8221;. Rzekoma autorka fejka straci&#322;a prac&#281;, a teraz pozywa tych, kt&#243;rzy nies&#322;usznie oskar&#380;yli. Sprawa dotyczy dzieci i pi&#281;knie obna&#380;a manipulacje zar&#243;wno prokuratora, medi&#243;w jak i samych rodzic&#243;w. <br><a href="https://gizmodo.com/deepfake-cheer-mom-sues-for-defamation-1850884295">LINK</a></p><blockquote><p>Porada &#8212; je&#347;li robicie g&#322;upie rzeczy, kt&#243;re kto&#347; mo&#380;e nagra&#263;, to za&#322;&#243;&#380;cie sobie pier&#347;cionek z dodatkowym palcem. Wtedy mo&#380;na bardziej wiarygodnie przekonywa&#263;, &#380;e to kompromituj&#261;ce nagranie z Wami to deepfake! </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UWi3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8de95b-49d9-4225-be13-a79259059414_1852x1252.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UWi3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8de95b-49d9-4225-be13-a79259059414_1852x1252.png 424w, https://substackcdn.com/image/fetch/$s_!UWi3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8de95b-49d9-4225-be13-a79259059414_1852x1252.png 848w, https://substackcdn.com/image/fetch/$s_!UWi3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8de95b-49d9-4225-be13-a79259059414_1852x1252.png 1272w, https://substackcdn.com/image/fetch/$s_!UWi3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8de95b-49d9-4225-be13-a79259059414_1852x1252.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UWi3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8de95b-49d9-4225-be13-a79259059414_1852x1252.png" width="374" height="252.75824175824175" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cf8de95b-49d9-4225-be13-a79259059414_1852x1252.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:984,&quot;width&quot;:1456,&quot;resizeWidth&quot;:374,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!UWi3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8de95b-49d9-4225-be13-a79259059414_1852x1252.png 424w, https://substackcdn.com/image/fetch/$s_!UWi3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8de95b-49d9-4225-be13-a79259059414_1852x1252.png 848w, https://substackcdn.com/image/fetch/$s_!UWi3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8de95b-49d9-4225-be13-a79259059414_1852x1252.png 1272w, https://substackcdn.com/image/fetch/$s_!UWi3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf8de95b-49d9-4225-be13-a79259059414_1852x1252.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></blockquote><div><hr></div><h2> 4. Zabij koledze iPhona</h2><p>Czyli exploit <a href="https://twitter.com/hack_git/status/1709525321479762337?s=12">crashuj&#261;cy iOS 17</a> (mo&#380;na klika&#263;, to nie link wprost do exploita, s&#322;owo harcerza!)</p><div><hr></div><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-010?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Bardzo nam pomo&#380;esz, je&#347;li udost&#281;pnisz linka do naszego newslettera znajomym z pracy np. na firmowym Slacku, a jak jeste&#347; odwa&#380;ny, to w Jirze ;) Niech te&#380; stan&#261; si&#281; bezpieczniejsi!</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-010?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://niebezpiecznik.substack.com/p/cyberexpress-010?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><h2>5. U&#380;ywaj&#261; dzieci, aby ograniczy&#263; nam prywatno&#347;&#263;  </h2><p>Doskona&#322;e &#347;ledztwo dziennikarskie, pokazuj&#261;ce kto naprawd&#281; sponsoruje i stoi za grupami domagaj&#261;cymi si&#281; od Apple os&#322;abienia prywatno&#347;ci i szyfrowania poniewa&#380; &#8220;<em>musimy chroni&#263; dzieci przed z&#322;ymi lud&#378;mi!</em>&#8221;. <br><a href="https://theintercept.com/2023/10/01/apple-encryption-iphone-heat-initiative/">LINK</a></p><div><hr></div><h2>6. Rosjanie opublikowali adresy tajnych lokali  </h2><p>Dobrze wiedzie&#263;, &#380;e nie tylko w Polsce urz&#281;dnicy potrafi&#261; ujawni&#263; adresy miejsc&#243;wek powi&#261;zanych ze s&#322;u&#380;bami specjalnymi&#8230; W Rosji adresy znajdowa&#322;y si&#281;&nbsp;na li&#347;cie &#8220;obiekt&#243;w, kt&#243;rym ograniczenie dostaw pr&#261;du spowoduje spore spo&#322;eczne problemy&#8221; :-)<br><a href="https://twitter.com/nexta_tv/status/1708801052756082758?s=12&amp;t=tBk3p1YTm23nIPZbu2sE1Q">LINK</a></p><div><hr></div><h2>7. Hackowali satelity, aby oszukiwa&#263; bukmacher&#243;w </h2><p>Opis rozbicia szajki oszust&#243;w, kt&#243;ra wykorzystywa&#322;a op&#243;&#378;nienia w sygnale satelitarnym do oszustw na zak&#322;adach sportowych. Czyli opis tego, ile mo&#380;na zarobi&#263; maj&#261;c 20 sekund wi&#281;cej&#8230;<br><a href="https://www.hackread.com/crooks-exploited-satellite-tech-betting-scheme/">LINK</a></p><div><hr></div><h2>8. Jak &#322;ama&#263; piny do aplikacji?</h2><p>Instrukcja z u&#380;yciem Flippera Zero, ale tak naprawd&#281; z instrukcj&#261; jak to z robi&#263; nawet je&#347;li si&#281;&nbsp;flippera nie posiada.<br><a href="https://twitter.com/androidmalware2/status/1704039116550144097?s=12&amp;t=tBk3p1YTm23nIPZbu2sE1Q">LINK</a></p><div class="poll-embed" data-attrs="{&quot;id&quot;:108583}" data-component-name="PollToDOM"></div><div><hr></div><h2>9. Analiza Googlowego &#8220;Sandbox Privacy&#8221; </h2><p>Pod k&#261;tem prywatno&#347;ci, wykonana przez lcamtufa, kt&#243;ry w Google d&#322;ugo pracowa&#322;, a kt&#243;rego ju&#380; googlowy zesp&#243;&#322; PR nie kontroluje :)<br><a href="https://infosec.exchange/@lcamtuf/111171721580683406">LINK</a></p><div><hr></div><h2>10. Skrypt kradn&#261;cy klucze Bitlockera</h2><p>Skrypt automatyzuj&#261;cy ekstrakcj&#281; kluczy &#8220;recovery&#8221; z wszystkich komputer&#243;w z domeny.<br><a href="https://github.com/p0dalirius/ExtractBitlockerKeys">LINK</a></p><div><hr></div><h2>11. Analiza linuksowego backdoora</h2><p>Wskazuje, &#380;e jest prosto z Chin i prawie jak z Windowsa.<br><a href="https://arstechnica.com/security/2023/09/never-before-seen-linux-backdoor-is-a-windows-malware-knockoff/">LINK</a></p><div><hr></div><h2>12. Niekasowalne wideo dla doros&#322;ych na YouTube  </h2><p>Pewna grupa odkry&#322;a, &#380;e mo&#380;na za pomoc&#261;<a href="https://twitter.com/niebezpiecznik/status/1709238133722661194"> odpowiedniej tre&#347;ci tagu</a> dodanego do wgrywanego na YouTube filmu spowodowa&#263;, &#380;e filmu nie b&#281;dzie si&#281;&nbsp;da&#322;o skasowa&#263;. Nawet je&#347;li konto autora zostanie zabanowane. I zacz&#281;li wgrywa&#263; wiadomo-co.</p><div><hr></div><h2>13. Zabezpiecz Discorda i Telegrama </h2><p>Opis tego, co w&#322;&#261;czy&#263; a co wy&#322;&#261;czy&#263;, &#380;eby bezpieczniej korzysta&#263; z Discorda i Telegrama.  <br><a href="https://officercia.mirror.xyz/dlf6ZEXq3FLE21ZY2jeJ0cBDyuZu8XIF9DEJAQ07nk8">LINK</a></p><div><hr></div><h2>== RAPORTY ==</h2><p>Tym razem raport b&#281;dzie tylko jeden <a href="https://www.microsoft.com/en-us/security/security-insider/microsoft-digital-defense-report-2023">od Microsoftu</a>. Za to dorzucamy <a href="https://twitter.com/LiveOverflow/status/1703297482317316187">playlist&#281;</a> wielu wyk&#322;ad&#243;w z bezpiecze&#324;stwa IT. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Przeczyta&#322;e&#347; prawie ca&#322;y &#128642; CyberExpress (newsletter Niebezpiecznika)! Gratulacje! Je&#347;li nie otrzymujesz go na maila, to wpisz sw&#243;j adres poni&#380;ej, a zaczniesz go otrzymywa&#263; :-)</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>== Autopropaganda ==</h2><p>Istotne tre&#347;ci z Niebezpiecznika z minionych (tygo)dni: </p><ul><li><p><a href="https://niebezpiecznik.pl/post/cyberberbezpieczny-samorzad-zaaplikuj-i-wez-udzial-w-naszych-szkoleniach-za-darmo/">Darmowe szkolenia dla urz&#281;dnik&#243;w</a>.  Niebawem ko&#324;czy si&#281; czas na zg&#322;oszenie, wi&#281;c je&#347;li pracujecie w urz&#281;dzie, nie przegapcie! </p></li><li><p>Historia naszego czytelnika, a raczej jego c&#243;rki &#8212; okradzionej z iPhona. Zobaczcie <a href="https://niebezpiecznik.pl/post/ukradli-jej-zablokowanego-iphona-ale-pozniej-wykazali-sie-kreatywnoscia/">jak z&#322;odzieje pr&#243;bowali odblokowa&#263; ukradzionego iPhona</a>.</p></li><li><p>O <a href="https://niebezpiecznik.pl/post/ataki-polska-kolej-pkp-radiostop/">parali&#380;u na polskiej kolei</a>, i tym, &#380;e nie stoj&#261; za nim hakerzy.</p></li><li><p>Przeanalizowali&#347;my programy wyborcze kluczowych partii pod k&#261;tem cyberbezpiecze&#324;stwa. Zobaczcie <a href="https://niebezpiecznik.pl/post/cyberbezpieczenstwo-w-programach-wyborczych-polskich-partii/">co kto proponuje</a>. A kto nie proponuje niczego. I sprawd&#378;cie w rz&#261;dowym rejestrze wyborc&#243;w, czy na pewno jeste&#347;cie przypisani do tej komisji, do kt&#243;rej my&#347;licie, &#380;e jeste&#347;cie. Je&#347;li nie, mo&#380;ecie to trzema klikni&#281;ciami zmieni&#263; <a href="https://www.gov.pl/web/gov/zmien-miejsce-glosowania?fbclid=IwAR05WmW0hXEn1whsUIvSFu8p9_kbyJawDDKfHzQhonrCDyHdVhFCOZ6lcSU">tutaj</a>.</p><p></p></li></ul><h2>* * *</h2><p>I to tyle na dzi&#347;. Jeszcze tylko &#347;mieszny obrazek i ko&#324;czymy:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Fdwo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30d63ab3-64e2-401b-b814-0d46c0d48f04_500x500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Fdwo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30d63ab3-64e2-401b-b814-0d46c0d48f04_500x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Fdwo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30d63ab3-64e2-401b-b814-0d46c0d48f04_500x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Fdwo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30d63ab3-64e2-401b-b814-0d46c0d48f04_500x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Fdwo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30d63ab3-64e2-401b-b814-0d46c0d48f04_500x500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Fdwo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30d63ab3-64e2-401b-b814-0d46c0d48f04_500x500.jpeg" width="500" height="500" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/30d63ab3-64e2-401b-b814-0d46c0d48f04_500x500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:500,&quot;width&quot;:500,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:64881,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Fdwo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30d63ab3-64e2-401b-b814-0d46c0d48f04_500x500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Fdwo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30d63ab3-64e2-401b-b814-0d46c0d48f04_500x500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Fdwo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30d63ab3-64e2-401b-b814-0d46c0d48f04_500x500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Fdwo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30d63ab3-64e2-401b-b814-0d46c0d48f04_500x500.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>PS. Pami&#281;tasz jeszcze kto by&#322; <a href="https://www.idc.com/eu/events/71057-idc-cloud-security?_gl=1*1d4agpn*_gcl_au*MTA4NTgxODExMS4xNjkyNzg0NjM5*_ga*MTUyNzM3OTMyLjE2MzM1OTk4MzY.*_ga_541ENG1F9X*MTY5NjMyNDY4MS4yMjkuMS4xNjk2MzI2MzY0LjU0LjAuMA..">sponsorem</a> tego wydania?<br><br><em>Dobra, koniec. <br>Bezpiecznego weekendu!</em></p>]]></content:encoded></item><item><title><![CDATA[CyberExpress #009 (26-03-2023)]]></title><description><![CDATA[W tym wydaniu du&#380;o mi&#281;sa, 2 linki premium i sporo o (wpadkach) s&#322;u&#380;b. Masa raport&#243;w, naprawd&#281; dobrych +przydatne narz&#281;dzia. Lektura zajmie Ci 3 minuty wi&#281;cej ni&#380; zwykle bo jest 2x wi&#281;cej ni&#380; zwykle ;)]]></description><link>https://niebezpiecznik.substack.com/p/cyberexpress-009-26-03-2023</link><guid isPermaLink="false">https://niebezpiecznik.substack.com/p/cyberexpress-009-26-03-2023</guid><dc:creator><![CDATA[Niebezpiecznik]]></dc:creator><pubDate>Sun, 26 Mar 2023 18:58:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F235708e3-6a88-422e-afcd-ad893fec7910_1000x667.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>To wydanie CyberExpressu jest do&#347;&#263; niecodzienne, bo &#8212; po pierwsze &#8212; tak du&#380;o ostatnio si&#281; u nas dzia&#322;o, &#380;e w zesz&#322;ym tygodniu nie dali&#347;my rady przygotowa&#263; CyberExpressu&#8230; :( Ale za to w tym wydaniu nadrabiamy liczb&#261; link&#243;w! :-) A po drugie &#8212; w CyberExpressie premier&#281; ma sekcja sponsorska! </p><blockquote><p>A pierwszym sponsorem jest serwis <a href="https://chronpesel.pl/?utm_source=newsletter&amp;utm_medium=niebezpiecznik&amp;utm_campaign=chp_marzec">ChronPESEL.pl</a>, dzi&#281;ki kt&#243;remu mo&#380;ecie zosta&#263; ostrze&#380;eni, kiedy kto&#347; pos&#322;u&#380;y si&#281; Waszymi danymi w celu wy&#322;udzenia. Jak to dzia&#322;a? Otrzymujecie SMS za ka&#380;dym razem, kiedy kto&#347; sprawdza Wasz PESEL w bazie KRD. Je&#347;li to nie Wy w&#322;a&#347;nie wnioskujecie o jak&#261;&#347; po&#380;yczk&#281; lub kredyt, to SMS jest sygna&#322;em, &#380;e <strong>dosz&#322;o do pr&#243;by wy&#322;udzenia</strong>. ChronPESEL zapewnia Wam wtedy kontakt z konsultantami, kt&#243;rzy w tej sytuacji przeprowadz&#261; Was przez kroki, jakie nale&#380;y wykona&#263;. Dodatkowo ChronPESEL umo&#380;liwia <a href="https://chronpesel.pl/?utm_source=newsletter&amp;utm_medium=niebezpiecznik&amp;utm_campaign=chp_marzec">pobranie raportu zbiorczego za 12 miesi&#281;cy</a> wstecz oraz monitoruje, czy Wasze dane nie zosta&#322;y ujawnione gdzie&#347; w internecie bez Waszej zgody. </p></blockquote><p>Brzmi ciekawie? Szczeg&#243;&#322;y us&#322;ugi znajdziecie <a href="https://chronpesel.pl/?utm_source=newsletter&amp;utm_medium=niebezpiecznik&amp;utm_campaign=chp_marzec">na tej stronie &#8212; rzu&#263;cie okiem,</a> a my dzi&#281;kujemy serwisowi ChronPESEL za wsparcie CyberExpressu! </p><div class="pullquote"><p>Pomy&#347;leli&#347;my, &#380;e ten &#8220;achievement unlocked&#8221; nale&#380;y uczci&#263;. Wi&#281;c zawsze jak b&#281;dzie sponsor to podrzucimy Wam w nagrod&#281; <strong>2 materia&#322;y premium</strong>, takie, kt&#243;rymi dzielimy si&#281; tylko z uczestnikami naszych p&#322;atnych szkole&#324;; takie, kt&#243;re przekazuj&#261; konkretn&#261;, praktyczn&#261; wiedz&#281;:</p><ol><li><p><a href="https://github.com/Ignitetechnologies/Mindmap">Zestaw map my&#347;li z cyberbezpiecze&#324;stwa </a></p></li><li><p><a href="https://github.com/V33RU/IoTSecurity101">IoT Security</a> &#8212; pot&#281;&#380;ny zbi&#243;r wiedzy, narz&#281;dzia, tutoriale, wszystko!</p></li></ol><p>Fajne linki? To podzi&#281;kujcie sponsorowi <a href="https://chronpesel.pl/?utm_source=newsletter&amp;utm_medium=niebezpiecznik&amp;utm_campaign=chp_marzec">klikaj&#261;c tutaj</a> &#128526;</p></div><p>Je&#347;li Wasza firma te&#380; chcia&#322;aby pojawi&#263; si&#281;&nbsp;w sekcji sponsorskiej i wspom&#243;c rozw&#243;j tego newslettera, napiszcie do nas na <em>cyberexpress@niebezpiecznik.pl</em></p><h2>Autopropaganda</h2><p>Zanim przejdziemy do zestawu najgor&#281;tszych temat&#243;w z ostatnich dni, kr&#243;tki przegl&#261;d tego, co opublikowali&#347;my na Niebezpieczniku od ostatniego wydania: </p><ul><li><p>Historia jednego z nas, Kamila. Cho&#263; jest on &#347;wiadomy zagro&#380;e&#324;, to da&#322; si&#281;&nbsp;podej&#347;&#263; w tzw. ataku &#8220;na BLIK-a&#8221;. Kamil <a href="https://niebezpiecznik.pl/post/historia-kamila-ktorego-okradziono-na-blik-a/">opisa&#322; dlaczego si&#281; nie zorientowa&#322;</a>. Niech to b&#281;dzie otrze&#378;wiaj&#261;ca lektura dla wszystkich, kt&#243;rzy uwa&#380;aj&#261;, &#380;e jak potrafi&#261; rozpozna&#263; phishing, to nie da si&#281; ich okra&#347;&#263;. </p></li><li><p>Ujawnili&#347;my dziur&#281; w CMS-ie wykorzystywanym przez wiele rz&#261;dowych serwis&#243;w (m.in. NFZ). Kto&#347; przy jej pomocy odsy&#322;a&#322; obywateli <a href="https://niebezpiecznik.pl/post/strony-rzadowe-zhackowane-wyniki-302/">na niezbyt przyzwoite strony</a>&#8230;</p></li><li><p>Przeanalizowali&#347;my <a href="https://niebezpiecznik.pl/post/okradziona-na-zdalny-pulpit-nie-musi-splacac-174-000-pln-zapadl-wyrok/">wyrok s&#261;du w sprawie ofiary, kt&#243;r&#261; okradziono &#8220;na pracownika banku&#8221;</a>. W artykule opis tego, co trzeba spe&#322;ni&#263;, aby odzyska&#263; od banku pieni&#261;dze po takiej kradzie&#380;y.</p></li><li><p>Ostrzegali&#347;my, &#380;e <a href="https://niebezpiecznik.pl/post/ktos-sie-pod-nas-podszywa/">kto&#347;&nbsp;si&#281;&nbsp;pod nas podszywa</a> i spamuje na Telegramie linkiem do ciekawej petycji&#8230;</p></li><li><p>Ostrzegali&#347;my te&#380; w&#322;a&#347;cicieli telefon&#243;w Samsunga przed <a href="https://niebezpiecznik.pl/post/masz-tego-smartfona-natychmiast-wylacz-te-dwa-ustawienia/">a&#380; 18 (!) powa&#380;nymi dziurami</a> &#8212; w tej sprawie wys&#322;ali&#347;my te&#380; <a href="https://niebezpiecznik.pl/app">CyberAlert</a></p></li><li><p>Opisali&#347;my kampani&#281; na polskie szpitale i inne plac&#243;wki zdrowia. Kto&#347; przez kilka dni z rz&#281;du&nbsp;<a href="https://niebezpiecznik.pl/post/ktos-atakuje-polskie-placowki-ochrony-zdrowia-na-wyciek-z-nfz/">w wybitnie dopracowany spos&#243;b podszywa&#322; si&#281; pod NFZ, ZUS oraz firm&#281;&nbsp;Kamsoft</a> aby zainfekowa&#263;&nbsp; i wy&#322;udzi&#263; dane dost&#281;powe do medycznych system&#243;w IT. W tych systemach s&#261; dane kontaktowe i dane o zdrowiu Polak&#243;w. Kto i do czego potrzebuje tych danych? &#129300;</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xxDA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F235708e3-6a88-422e-afcd-ad893fec7910_1000x667.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xxDA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F235708e3-6a88-422e-afcd-ad893fec7910_1000x667.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xxDA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F235708e3-6a88-422e-afcd-ad893fec7910_1000x667.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xxDA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F235708e3-6a88-422e-afcd-ad893fec7910_1000x667.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xxDA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F235708e3-6a88-422e-afcd-ad893fec7910_1000x667.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xxDA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F235708e3-6a88-422e-afcd-ad893fec7910_1000x667.jpeg" width="418" height="278.806" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/235708e3-6a88-422e-afcd-ad893fec7910_1000x667.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:667,&quot;width&quot;:1000,&quot;resizeWidth&quot;:418,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="https://substackcdn.com/image/fetch/$s_!xxDA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F235708e3-6a88-422e-afcd-ad893fec7910_1000x667.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xxDA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F235708e3-6a88-422e-afcd-ad893fec7910_1000x667.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xxDA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F235708e3-6a88-422e-afcd-ad893fec7910_1000x667.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xxDA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F235708e3-6a88-422e-afcd-ad893fec7910_1000x667.jpeg 1456w" sizes="100vw" loading="lazy" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>We wtorek ruszyli&#347;my te&#380; z nowym szkoleniem pt. <a href="https://niebezpiecznik.pl/post/cyber-ratownik-czyli-o-tym-jak-firmy-powinny-reagowac-na-incydenty-w-firmach/">Cyber Ratownik, First Incident Responder</a> &#128735;. Szkolenie jest <strong>silnie praktyczne</strong> i uczy jak wykrywa&#263;&nbsp;w&#322;amania do firmowych sieci oraz jak je <strong>poprawnie</strong> analizowa&#263;, by po zostawionych przez atakuj&#261;cych &#347;ladach ustali&#263; faktyczny przebieg ataku i to, do czego w&#322;amywacze mieli dost&#281;p. Ta wiedza jest potrzebna, o czym &#347;wiadczy to, &#380;e pierwszy termin wyprzeda&#322; si&#281; <strong>w kilka godzin</strong> &#128561; &#8212; uruchomili&#347;my wi&#281;c kolejne terminy, ale zosta&#322;y na nich ostatnie wolne miejsca. Dlatego, je&#347;li temat Ci&#281; interesuje, <a href="https://niebezpiecznik.pl/post/cyber-ratownik-czyli-o-tym-jak-firmy-powinny-reagowac-na-incydenty-w-firmach/">zapoznaj si&#281;&nbsp;z opisem szkolenia i zarezerwuj sobie miejsce</a>.    </p><p>A teraz, pora na linki!</p><h2>1. Acropalypse, czyli odcropuj screenshot</h2><p>Najpierw <a href="https://www.da.vidbuchanan.co.uk/blog/exploiting-acropalypse.html">ujawniono</a>, &#380;e da si&#281;&nbsp;odzyskiwa&#263; obci&#281;te obszary na screenshotach ze smartfon&#243;w Pixel, a potem okaza&#322;o si&#281;, &#380;e podobny b&#322;&#261;d znajduj&#281; si&#281; tak&#380;e w <a href="https://twitter.com/david3141593/status/1638222624084951040">Windowsie 11</a>. #prywatno&#347;&#263;</p><div><hr></div><h2>2. Zagro&#380;enia dotycz&#261;ce NO-CODE i LOW-CODE</h2><p>Lista rzeczy, kt&#243;re warto uwzgl&#281;dni&#263; pod k&#261;tem bezpiecze&#324;stwa, je&#347;li Wasza firma tworzy oprogramowanie w coraz popularniejszym podej&#347;ciu low-code lub no-code.<br><a href="https://owasp.org/www-project-top-10-low-code-no-code-security-risks/">LINK</a></p><div><hr></div><h2>3. Wi-Fi pozwala zagl&#261;da&#263; za &#347;ciany </h2><p>O tym jak wykorzysta&#263; Wi-Fi do wykrywanie ruch&#243;w ludzi w budynkach<br><a href="https://medium.com/syncedreview/cmus-densepose-from-wifi-an-affordable-accessible-and-secure-approach-to-human-sensing-6440173e9795">LINK</a></p><div><hr></div><h2>4. Admin BreachForum aresztowany</h2><p>Zatrzymano Pompompurina, a jego zast&#281;pca zamkn&#261;&#322; forum w zwi&#261;zku z ryzykiem infiltracji przez FBI. <a href="https://www.hackread.com/breach-forums-owner-pompompurin-arrested-new-york/">LINK1 </a>oraz <a href="https://peekskillherald.com/7107/news/fbi-arrests-alleged-cybercriminal-in-peekskill/">LINK2</a>, plus ciekawa analiza zatrzymania <a href="https://www.databreaches.net/was-there-a-rush-to-arrest-pompompurin-the-owner-of-breachforums-if-so-why/">LINK3</a>. &#379;eby by&#322;o &#347;mieszniej, go&#347;&#263; <a href="https://twitter.com/emptywheel/status/1639269358663761922">zdoxowa&#322; si&#281; sam</a> &#129400;</p><div><hr></div><h2>5. Ro&#347;nie liczba atak&#243;w na kancelarie prawne </h2><p>W Polsce atakuj&#261; bran&#380;&#281; medyczn&#261;, a w USA coraz wi&#281;cej <a href="https://twitter.com/laughing_mantis/status/1633632271982010370?s=12">atak&#243;w na firmy prawnicze</a>. Obydwa sektory to &#380;y&#322;a z&#322;ota. I obydwa sektory nie nale&#380;&#261; do najlepiej zabezpieczonych&#8230;</p><div><hr></div><h2>6. &#379;enuj&#261;ca wpadka rosyjskich s&#322;u&#380;b</h2><p>Pr&#243;bowali wrobi&#263; Esto&#324;czyka, ale mieli pecha, bo nie sprawdzili, &#380;e go&#347;&#263; by&#322; w wi&#281;zieniu &#128514; <br><a href="https://news.yahoo.com/how-russias-security-service-framed-an-estonian-prisoner-as-a-secret-agent-100034403.html">LINK</a></p><div><hr></div><h2>7. Wyszukiwarka biometryczna twarzy</h2><p>Pozwala namierzy&#263; inne zdj&#281;cia danej osoby i jej konta w r&#243;&#380;nych serwisach internetowych. Wystarczy fotka twarzy. Sprawd&#378;cie siebie, mo&#380;e znajdziecie co&#347;, czego nie powinno si&#281; da&#263; znale&#378;&#263; na Wasz temat. A mo&#380;e dowiecie si&#281;, &#380;e macie sobowt&#243;ra :-)<br><a href="https://facecheck.id/">LINK</a></p><div><hr></div><h2>8. Techniki omijania antywirus&#243;w</h2><p>Bardzo rozbudowana mapa my&#347;li z linkami do opis&#243;w ka&#380;dej z technik.<br><a href="https://cmepw.github.io/BypassAV/">LINK</a></p><div><hr></div><h2>9. OSINT w s&#322;u&#380;bie przest&#281;pc&#243;w</h2><p>Wci&#261;gaj&#261;ca opowie&#347;&#263; o tym jak jeden gang u&#380;ywa&#322; technik OSINT-u do wytropienia i wymordowania lidera konkurencyjnego gangu.<br><a href="https://www.occrp.org/en/balkan-cocaine-wars/how-a-montenegrin-gang-used-open-source-intelligence-to-kill">LINK</a></p><div><hr></div><h2>9. U&#380;ywasz Bitwardena?</h2><p>To poczytaj o tym <a href="https://www.bleepingcomputer.com/news/security/bitwarden-flaw-can-let-hackers-steal-passwords-using-iframes/">ataku z ramk&#261;</a>, kt&#243;ry mo&#380;e przechwyci&#263; Twoje has&#322;o. </p><div><hr></div><h2>10. Jak &#322;apa&#263; przest&#281;pc&#243;w wyszukiwark&#261;?</h2><p>A raczej, jak namierza&#263; dziurawe/zhackowane serwery, na kt&#243;rych ci przest&#281;pcy ju&#380;&nbsp;s&#261;. Instrukcja z u&#380;yciem wyszukiwarki QUAKE.<br><a href="https://gustavshen.medium.com/use-searching-engines-to-hunt-for-threat-actors-74be52976e9f">LINK</a></p><div><hr></div><h2>11. Hackowanie AI od Binga</h2><p>Poprzez umieszczenie prompt-injecta w tre&#347;ci strony internetowej. <br><a href="https://twitter.com/random_walker/status/1636923058370891778?s=12">Zabawne</a>.</p><div><hr></div><h2>12. Implantowanie dock&#243;w USB </h2><p>Techniczny <a href="https://research.aurainfosec.io/pentest/threat-on-your-desk-evil-usbc-dock/">przewodnik</a> tworzenia implanta w takiej przej&#347;ci&#243;wce:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PU8j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55bac432-99ca-4432-a8d2-b7ace512fce2_767x505.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PU8j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55bac432-99ca-4432-a8d2-b7ace512fce2_767x505.jpeg 424w, https://substackcdn.com/image/fetch/$s_!PU8j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55bac432-99ca-4432-a8d2-b7ace512fce2_767x505.jpeg 848w, https://substackcdn.com/image/fetch/$s_!PU8j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55bac432-99ca-4432-a8d2-b7ace512fce2_767x505.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!PU8j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55bac432-99ca-4432-a8d2-b7ace512fce2_767x505.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PU8j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55bac432-99ca-4432-a8d2-b7ace512fce2_767x505.jpeg" width="374" height="246.245110821382" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/55bac432-99ca-4432-a8d2-b7ace512fce2_767x505.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:505,&quot;width&quot;:767,&quot;resizeWidth&quot;:374,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!PU8j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55bac432-99ca-4432-a8d2-b7ace512fce2_767x505.jpeg 424w, https://substackcdn.com/image/fetch/$s_!PU8j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55bac432-99ca-4432-a8d2-b7ace512fce2_767x505.jpeg 848w, https://substackcdn.com/image/fetch/$s_!PU8j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55bac432-99ca-4432-a8d2-b7ace512fce2_767x505.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!PU8j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55bac432-99ca-4432-a8d2-b7ace512fce2_767x505.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>13. Analiza sprz&#281;towego keyloggera</h2><p>Pozostaj&#261;c w temacie sprz&#281;tu, ciekawa analiza sprz&#281;towego keyloggera. <br><a href="https://www.synacktiv.com/en/publications/hardware-investigation-of-wireless-keyloggers.html">LINK</a></p><div><hr></div><h2>14. Jak ustrzec si&#281;&nbsp;przed rosyjskimi s&#322;u&#380;bami? </h2><p>Prezentacja z ostrze&#380;eniami od Agencji Wywiadu. Uwaga, to PPTX&#8230;<br><a href="https://www.gov.pl/web/sluzby-specjalne/jak-ustrzec-sie-przed-rosyjskimi-sluzbami">LINK</a></p><blockquote><p>Na marginesie, je&#347;li kogo&#347; interesuje to jakimi technikami werbuj&#261; s&#322;u&#380;by, to rzu&#263;cie okiem na <a href="https://sklep.niebezpiecznik.pl/opis/22">to nagranie webinaru</a>, kt&#243;re par&#281; miesi&#281;cy temu zrobili&#347;my z Tomkiem Aw&#322;asewiczem, autorem ksi&#261;&#380;ek dokumentalnych o szpiegach.</p><div><hr></div></blockquote><h2>15. Pocz&#261;tki phishingu</h2><p>Bardzo <a href="https://arxiv.org/ftp/arxiv/papers/1106/1106.4692.pdf">ciekawa praca naukowa</a>.</p><div><hr></div><h2>16. Jak holenderska policja wykiwa&#322;a gang ransomware&#8217;owy</h2><p>I <a href="https://blog.chainalysis.com/reports/deadbolt-ransomware-strain-tricked-into-giving-up-decryption-keys/">wy&#322;udzi&#322;a</a> klucze dla ofiar. Bo blokczejn trudny jest! </p><div><hr></div><h2>17. Gang ransomware z Rosji ujawni&#322; zdj&#281;cia pacjent&#243;w chorych na raka</h2><p>Fotki <a href="https://arstechnica.com/information-technology/2023/03/ransomware-attacks-have-entered-a-heinous-new-phase/">opublikowa&#322;y szumowiny z BackCat</a>a, a teraz poszkodowani pacjenci <a href="https://www.theregister.com/2023/03/15/cancer_lvhn_sues_hospital/">pozywaj&#261; szpital</a>. Mamy nadziej&#281;, &#380;e tymi gnidami z BlackCata kto&#347;&nbsp;szybko zrobi porz&#261;dek. </p><div><hr></div><h2>18. Bolesna wpadka agenta FBI</h2><p>Wys&#322;a&#322; obro&#324;com oskar&#380;onego duuuu&#380;ego Excela z tajnym i po cz&#281;&#347;ci tak&#380;e kompromituj&#261;cym FBI materia&#322;em. Przypadek?<br><a href="https://infosec.exchange/@micahflee/110018404032592698">LINK</a></p><div><hr></div><h2>19. Techniczny opis hackowania Pixeli</h2><p>I to w <a href="https://twitter.com/0xor0ne/status/1632297423211986944?s=12">3 cz&#281;&#347;ciach</a>. To dla tych raczej zaawansowanych i niskopoziomowych. Chcecie wi&#281;cej takiego &#8220;mi&#281;ska&#8221;? To zagwiazdkujcie to wydanie newslettera ;)</p><div><hr></div><h2>20. Jak bia&#322;oruscy partyzanci troluj&#261; Rosjan</h2><p>Bia&#322;oruscy partyzanci lataj&#261;&nbsp;sobie dronem po &#8220;pilnie strze&#380;onym&#8221; wojskowym lotnisku i dosiadaj&#261; nim rosyjskiego AWACS A-50U :)</p><div id="youtube2--SoqX8YRJb4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;-SoqX8YRJb4&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/-SoqX8YRJb4?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><div><hr></div><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-009-26-03-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Czytasz &#128642; CyberExpress (newsletter Niebezpiecznika). Bardzo nam pomo&#380;esz, je&#347;li udost&#281;pnisz linka do tego newslettera znajomym z pracy! Niech te&#380; stan&#261; si&#281; bezpieczniejsi!</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-009-26-03-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://niebezpiecznik.substack.com/p/cyberexpress-009-26-03-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><h2>21. AT&amp;T potrafi &#347;ledzi&#263; pozycj&#281; samochod&#243;w</h2><p>Wystarczy <a href="https://twitter.com/iblametom/status/1635369087084945408?s=12">poda&#263; numer VIN auta</a>. Czy&#380;by producenci samochod&#243;w przekazywali numery VIN operatorom wbudowanych w samochody modu&#322;&#243;w SIM!?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yWX-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7175354-433c-489a-9bd6-6afdcf291947_1200x609.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yWX-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7175354-433c-489a-9bd6-6afdcf291947_1200x609.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yWX-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7175354-433c-489a-9bd6-6afdcf291947_1200x609.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yWX-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7175354-433c-489a-9bd6-6afdcf291947_1200x609.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yWX-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7175354-433c-489a-9bd6-6afdcf291947_1200x609.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yWX-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7175354-433c-489a-9bd6-6afdcf291947_1200x609.jpeg" width="538" height="273.035" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c7175354-433c-489a-9bd6-6afdcf291947_1200x609.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:609,&quot;width&quot;:1200,&quot;resizeWidth&quot;:538,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="https://substackcdn.com/image/fetch/$s_!yWX-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7175354-433c-489a-9bd6-6afdcf291947_1200x609.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yWX-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7175354-433c-489a-9bd6-6afdcf291947_1200x609.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yWX-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7175354-433c-489a-9bd6-6afdcf291947_1200x609.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yWX-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc7175354-433c-489a-9bd6-6afdcf291947_1200x609.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>22. Dziura w Outlooku </h2><p>Zdecydowanie jeden z wa&#380;niejszych temat&#243;w minionego tygodnia, czyli <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397">CVE-2023-23397</a>, kt&#243;ra by&#322;a wykorzystywana przez Rosjan do atak&#243;w. Po publikacji patcha szybko pojawi&#322; si&#281; <a href="https://www.mdsec.co.uk/2023/03/exploiting-cve-2023-23397-microsoft-outlook-elevation-of-privilege-vulnerability/">exploit</a> i dobra <a href="https://www.reddit.com/r/crowdstrike/comments/11sda83/situational_awareness_hunting_microsoft_outlook/">analiza na Reddicie</a>. A wszystko co z tym atakiem i dziur&#261; zwi&#261;zane znajdziecie te&#380; <a href="https://www.huntress.com/blog/everything-we-know-about-cve-2023-23397">tutaj</a>.</p><div><hr></div><h2>== RAPORTY ==</h2><p>W tym tygodniu obrodzi&#322;o naprawd&#281; konkretnymi raportami! Wszystkie s&#261; szalenie ciekawe i je&#347;li starczy Wam czasu, to czytajcie je od deski do deski. Daj&#261;&nbsp;&#347;wietny obraz wydarze&#324; z minionego roku w &#8220;cyber&#8221; z r&#243;&#380;nych perspektyw, czyli &#347;wietnie si&#281; uzupe&#322;niaj&#261;. A je&#347;li czasu Wam nie starczy, to chocia&#380; je przescrollujcie, bo warto (no i wykresy kolorowe s&#261; ;)</p><ul><li><p><a href="https://go.crowdstrike.com/rs/281-OBQ-266/images/CrowdStrike2023GlobalThreatReport.pdf">Raport CrowdStrike podsumowuj&#261;cy 2022</a></p></li><li><p><a href="https://thedfirreport.com/2023/03/06/2022-year-in-review/">Raport DFIR podsumowuj&#261;cy 2022</a> </p></li><li><p><a href="https://resource.redcanary.com/rs/003-YRU-314/images/2023_ThreatDetectionReport_RedCanary.pdf">Raport Red Canary (Threat Detection) za 2022</a></p></li><li><p><a href="https://www.ic3.gov/Media/PDF/AnnualReport/2022_IC3Report.pdf">Raport FBI Internet Crime 2022</a></p></li><li><p><a href="https://cip.gov.ua/services/cm/api/attachment/download?id=53466">Cybertaktyki Rosji</a> &#8212; raport ukrai&#324;skiej Pa&#324;stwowej S&#322;u&#380;by &#321;&#261;czno&#347;ci Specjalnej i Ochrony Informacji</p></li><li><p><a href="https://www.microsoft.com/en-us/security/business/security-insider/wp-content/uploads/2023/03/A-year-of-Russian-hybrid-warfare-in-Ukraine_MS-Threat-Intelligence-1.pdf">Rok wojny hybrydowej w Ukrainie</a> - raport Microsoft Threat Intelligence</p></li><li><p><a href="https://www.wojsko-polskie.pl/woc/u/4c/d1/4cd11eaf-3567-405d-994f-f88b6b45ad0b/ukraina_2022_na_cyfrowym_froncie.pdf">Synteza kilku raport&#243;w o wojnie w Ukrainie</a> autorstwa naszych Wojsk Obrony Cyberprzestrzeni.</p></li><li><p><a href="https://www.aph.gov.au/DocumentStore.ashx?id=a7e2a076-1112-4414-ba0f-f129e0cd39fe&amp;subId=735418">113 stron o powiazaniach TikToka z rz&#261;dem Chi&#324;skim</a>. Analiza parlamentu australijskiego. W tym temacie warto jeszcze przeczyta&#263; <a href="https://www.utahbusiness.com/how-tiktok-algorithm-became-national-security-risk-united-states/">ten tekst</a>, kt&#243;ry wyja&#347;nia powody nielubienia TikToka.</p></li><li><p>Nie do ko&#324;ca raport, ale bardzo rozbudowana <a href="https://www.mandiant.com/resources/blog/lightshow-north-korea-unc2970">analiza dzia&#322;a&#324; p&#243;&#322;nocnokorea&#324;skich hacker&#243;w rz&#261;dowych</a> od Mandianta </p></li><li><p>Te&#380; nie do ko&#324;ca raport, ale warto rzuci&#263; okiem: <a href="https://www.youtube.com/watch?v=OBpsu5tXsUg">nagrania z konferencji BlueHat 2023</a></p><p></p></li></ul><h2>* * *</h2><p>I je&#347;li chodzi o merytoryk&#281;, to na dzi&#347; tyle. Poni&#380;ej znajdziecie &#347;mieszny (ale tym razem lekko hermetyczny) obrazek:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WJgw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d4ab49b-afd4-424a-ad8c-3bd2d59b57c4_308x512.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WJgw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d4ab49b-afd4-424a-ad8c-3bd2d59b57c4_308x512.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WJgw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d4ab49b-afd4-424a-ad8c-3bd2d59b57c4_308x512.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WJgw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d4ab49b-afd4-424a-ad8c-3bd2d59b57c4_308x512.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WJgw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d4ab49b-afd4-424a-ad8c-3bd2d59b57c4_308x512.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WJgw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d4ab49b-afd4-424a-ad8c-3bd2d59b57c4_308x512.jpeg" width="308" height="512" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4d4ab49b-afd4-424a-ad8c-3bd2d59b57c4_308x512.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:308,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:43347,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WJgw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d4ab49b-afd4-424a-ad8c-3bd2d59b57c4_308x512.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WJgw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d4ab49b-afd4-424a-ad8c-3bd2d59b57c4_308x512.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WJgw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d4ab49b-afd4-424a-ad8c-3bd2d59b57c4_308x512.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WJgw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d4ab49b-afd4-424a-ad8c-3bd2d59b57c4_308x512.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Z og&#322;osze&#324; parafialnych:</p><ul><li><p>Czat przez Substacka nie spe&#322;nia naszych oczekiwa&#324;. Nikt z tego nie korzysta i nie ma si&#281; co dziwi&#263;, bo mo&#380;na to robi&#263; tylko przez apk&#281;. Dlatego niebawem otworzymy Discorda. Zastanawiamy si&#281; tylko, czy robi&#263;&nbsp;osobny serwer, czy po prostu za&#322;o&#380;y&#263; dodatkowy CyberExpressowy kana&#322; i wpu&#347;ci&#263; Was na serwer,  do kt&#243;rego dost&#281;p maj&#261; uczestnicy naszych szkole&#324;? Jak s&#261;dzicie? <em>Przy okazji, ciekawy <a href="https://www.niemanlab.org/2023/03/how-bellingcat-gets-15000-people-on-discord-to-talk-about-investigative-journalism/">materia&#322;</a> o spo&#322;eczno&#347;ci Bellingcata na Discordzie.</em></p></li><li><p>Liczba subskrybent&#243;w CyberExpressu to ju&#380;&nbsp;prawie 7000 :-)</p></li><li><p>Pami&#281;tasz jeszcze kto by&#322; <a href="https://chronpesel.pl/?utm_source=newsletter&amp;utm_medium=niebezpiecznik&amp;utm_campaign=chp_marzec">sponsorem</a> tego wydania?</p></li></ul><p><br><em>Dobra, koniec. <br>Bezpiecznego tygodnia!</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Przeczyta&#322;e&#347; ca&#322;y &#128642; CyberExpress (newsletter Niebezpiecznika)! Gratulacje! Chyba jeste&#347; kim&#347; z naszej rodziny&#8230; ;) Ale je&#347;li nie &#8212; i nie otrzymujesz naszego newslettera na swojego maila &#8212; to wpisz go poni&#380;ej, a zaczniesz go otrzymywa&#263; :-)</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CyberExpress #008 (10-03-2023)]]></title><description><![CDATA[W tym wydaniu: fascynuj&#261;cy wywiad o &#380;yciu haker&#243;w w Rosji, kolejne "paranoje" USA na temat Chin, przy&#322;apanie FBI na kontrowersyjnych zakupach i bardzo istotne raporty. Lektura zajmie ci ok. 3 minuty.]]></description><link>https://niebezpiecznik.substack.com/p/cyberexpress-008-10-03-2023</link><guid isPermaLink="false">https://niebezpiecznik.substack.com/p/cyberexpress-008-10-03-2023</guid><dc:creator><![CDATA[Piotr Konieczny 👾]]></dc:creator><pubDate>Fri, 10 Mar 2023 13:22:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!RI8E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb043dbf6-beb7-486b-8d50-d231a8aee578_600x428.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Autopropaganda</h2><p>Zaczynamy od przegl&#261;du tego, co publikowali&#347;my na Niebezpieczniku w ostatnich dniach. A dzia&#322;o si&#281;&nbsp;sporo! </p><ul><li><p>Po raz pierwszy musieli&#347;my wys&#322;a&#263; <strong>kilka CyberAlert&#243;w jednego dnia</strong>. Obudzi&#322;a si&#281; jaka&#347; aktywna siatka oszust&#243;w. Od tygodnia regularnie wali pretekstami &#8220;<strong>na Allegro&#8221;</strong>. Ostrzegali&#347;my te&#380; przed kampani&#261;&nbsp;&#8220;<strong>na Revoluta</strong>&#8221; i &#8220;<strong>PKO</strong>&#8221;. Do&#347;&#263; ciekawym wektorem by&#322; <a href="https://niebezpiecznik.pl/post/uwaga-na-odszkodowania-po-oszustwie-internetowym/">phishing do ju&#380;&nbsp;okradzionych na OLX/Vinted</a>, kt&#243;rym przest&#281;pcy obiecywali &#8230;odszkodowanie :-D Bezczelno&#347;&#263; lvl milion.</p><blockquote><p><em><strong>Ka&#380;dy CyberAlert dociera&nbsp;ju&#380;&nbsp;do&nbsp;kilkuset tysi&#281;cy os&#243;b! <br></strong></em><strong><br>&#9888;&#65039; </strong>Zainstaluj nasz&#261; aplikacj&#281; <strong>CyberAlerty</strong> sobie i znajomym. Apka jest darmowa i nie wymaga &#380;adnej rejestracji, a jedyne co robi, to b&#322;yskawicznie ostrzega przed nowymi, istotnymi atakami, kt&#243;rych celem s&#261; dane lub pieni&#261;dze Polak&#243;w.<strong> <a href="https://niebezpiecznik.pl/app">Kliknij tutaj, aby ja&nbsp;pobra&#263; na Androida albo iPhona</a>.  &#9888;&#65039;</strong></p></blockquote></li><li><p>Tomasz Brol, kt&#243;rego filmik o <strong>balonach szpiegowskich </strong>linkowali&#347;my w  <a href="https://niebezpiecznik.substack.com/i/103850856/wojsko-zacze%C5%82o-strzelac-do-balonow-czy-to-ufo-czy-chinscy-szpiedzy">CyberExpress#004</a> przygotowa&#322; dla Was arcyciekawy artyku&#322; o tym<a href="https://niebezpiecznik.pl/post/balony-do-obrony-i-ataku-kulisy-operacji-outward-ktora-wylaczyla-prad-w-kilku-krajach/"> jak wykorzystano balony&nbsp;do obrony przed nalotami i &#8230;ataku na sieci energetyczne</a>. </p></li><li><p>Opisali&#347;my te&#380; coraz popularniejszy wektor ataku &#8212; &#8220;<strong>na ChatGPT</strong>&#8221; oraz z&#322;o&#347;liwe wtyczki i aplikacje, kt&#243;re udaj&#261; AI wykradaj&#261; dane. <a href="https://niebezpiecznik.pl/post/uwazaj-na-wtyczki-do-przegladarek-i-aplikacje-zwiazane-z-chatgpt-i-sztuczna-inteligencja/">Zobaczcie jak wygl&#261;da ten atak</a>.</p><blockquote><p>&#129302; Przygotowujemy <strong>webinar na temat Sztucznej Inteligencji</strong>, w kt&#243;rym chcemy przedstawi&#263; zar&#243;wno ryzyka AI jak i jej u&#380;yteczne zastosowania, w tym ju&#380;&nbsp;gotowe narz&#281;dzia, kt&#243;re z AI korzystaj&#261; i mog&#261; Wam pom&#243;c w &#380;yciu i w pracy. Aby go jak najlepiej dostosowa&#263; do Waszych potrzeb, prosimy o odpowied&#378; <a href="https://docs.google.com/forms/d/e/1FAIpQLSe9219jeeK-KxjVo1o0uM6yIWzwEpyRrbi04aRj2zQt0S3coA/viewform">na te 3 pytania</a>. Mo&#380;ecie te&#380; po prostu zapisa&#263; si&#281; na list&#281; powiadomie&#324; <a href="https://niebezpiecznik.pl/post/uwazaj-na-wtyczki-do-przegladarek-i-aplikacje-zwiazane-z-chatgpt-i-sztuczna-inteligencja/">tutaj</a> &#8212; jak ustalimy termin webinaru, dostaniecie od nas maila. &#129302;</p></blockquote></li><li><p>Wojciech Bielak, trener niebezpiecznikowego <a href="https://niebezpiecznik.pl/szkolenia/sdr-bezpieczenstwo-komunikacja-radiowa/?nsw">szkolenia z bezpiecze&#324;stwa komunikacji radiowej </a>opublikowa&#322; artyku&#322;&nbsp;na temat namierzania &#378;r&#243;de&#322; sygna&#322;u radiowego, w praktyce pokazuj&#261;c jak radiopelengacja kiedy&#347;&nbsp;pomaga&#322;&#261; zatapia&#263; niemieckie okr&#281;ty podwodne, a teraz u&#322;atwia robienie kuku Rosjanom. </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RI8E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb043dbf6-beb7-486b-8d50-d231a8aee578_600x428.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RI8E!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb043dbf6-beb7-486b-8d50-d231a8aee578_600x428.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RI8E!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb043dbf6-beb7-486b-8d50-d231a8aee578_600x428.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RI8E!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb043dbf6-beb7-486b-8d50-d231a8aee578_600x428.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RI8E!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb043dbf6-beb7-486b-8d50-d231a8aee578_600x428.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RI8E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb043dbf6-beb7-486b-8d50-d231a8aee578_600x428.jpeg" width="328" height="233.97333333333333" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b043dbf6-beb7-486b-8d50-d231a8aee578_600x428.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:428,&quot;width&quot;:600,&quot;resizeWidth&quot;:328,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RI8E!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb043dbf6-beb7-486b-8d50-d231a8aee578_600x428.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RI8E!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb043dbf6-beb7-486b-8d50-d231a8aee578_600x428.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RI8E!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb043dbf6-beb7-486b-8d50-d231a8aee578_600x428.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RI8E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb043dbf6-beb7-486b-8d50-d231a8aee578_600x428.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Polecamy <a href="https://niebezpiecznik.pl/post/radiopelengacja-rosjanie-hf-df-kraken/">lektur&#281; artyku&#322;u Wojtka</a>, kt&#243;ry prezentuje kilka tanich urz&#261;dze&#324;, z jakich sami mo&#380;ecie skorzysta&#263; do &#8220;rozejrzenia&#8221; si&#281;&nbsp;po okolicy. Zapraszamy te&#380; na warsztaty z Wojtkiem. Instrukcje w artykule.</p></li></ul><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading &#128642; CyberExpress (newsletter Niebezpiecznika)! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>No, m&#243;wili&#347;my, &#380;e du&#380;o si&#281;&nbsp;u nas dzia&#322;o. Na koniec wst&#281;pniaka jeszcze jedna kr&#243;tka informacja, z kt&#243;rej jeste&#347;my superdumni: </p><div class="pullquote"><p>ka&#380;de wydanie CyberExpressu trafia ju&#380;&nbsp;do ponad <strong>5 000 os&#243;b</strong>!  &#127881;</p></div><p>A teraz jedziemy z newsami:</p><h2>1. Wywiad o ruskich hakerach i ich &#8220;stosunkach z w&#322;adz&#261;&#8221; </h2><p>&#346;wietny! Opowiada by&#322;y pracownik firmy Group-IB, kt&#243;ry uciek&#322; z Rosji do Polski i obecnie tu mieszka.<br><a href="https://novayagazeta.eu/articles/2023/02/25/99-rossiiskikh-khakerov-kontroliruet-fsb">LINK</a> (&#127479;&#127482;)</p><h2>2. FBI przyznaje: kupujemy dane o lokalizacji u&#380;ytkownik&#243;w od firm reklamowych</h2><p>Kupili, &#380;eby nie musie&#263; stara&#263; si&#281;&nbsp;o nakazy s&#261;dowe i zawraca&#263;&nbsp;sobie g&#322;owy standardow&#261; rz&#261;dow&#261; papierkologi&#261; (oraz przede wszystkim ryzykowa&#263;, &#380;e im taki wniosek o masowe naruszenie prywatno&#347;ci odrzuc&#261;).<br><a href="https://www.wired.com/story/fbi-purchase-location-data-wray-senate">LINK</a></p><h2>3. Zreversowano protok&#243;&#322; wykorzystywany przez drony DJI do nadawania pozycji pilota</h2><p>Ten mechanizm (AreoScope) to &#380;adna nowo&#347;&#263; czy tajemnica. Wspominali&#347;my o nim <a href="https://niebezpiecznik.pl/post/amerykanie-uziemiaja-drony/">zar&#243;wno w 2022</a> roku jak i <a href="https://twitter.com/niebezpiecznik/status/1503471389562572800">na pocz&#261;tku wojny Rosji z Ukrain&#261;</a>. Kr&#243;tko potem Ukraina nauczy&#322;a si&#281;&nbsp;usuwa&#263; te szpiegowskie wstawki z firmware dron&#243;w, a chodz&#261; te&#380; s&#322;uchy, &#380;e <strong>spoofowa&#322;a</strong> nadawane koordynaty tak, &#380;e Rosjanie bombardowali samych siebie :-&gt;<br><a href="https://www.wired.com/story/dji-droneid-operator-location-hacker-tool/">LINK</a></p><h2>4. USA uwa&#380;a, &#380;e Chiny szpieguj&#261; ich nie tylko balonami, ale te&#380; portowymi &#380;urawiami. </h2><p>Bo te s&#261; produkowane w Chinach i naszpikowane elektronik&#261; oraz ciekawymi sensorami.<br><a href="https://www.wsj.com/articles/pentagon-sees-giant-cargo-cranes-as-possible-chinese-spying-tools-887c4ade">LINK</a></p><h2>5. Pegasus by&#322; wykorzystywany do szpiegowania obywateli </h2><p>Tym razem przez Meksyka&#324;sk&#261; armi&#281;. <br><a href="https://citizenlab.ca/2022/10/new-pegasus-spyware-abuses-identified-in-mexico/">LINK</a></p><div><hr></div><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-008-10-03-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Czytasz &#128642; CyberExpress (newsletter Niebezpiecznika). Bardzo nam pomo&#380;esz, je&#347;li go udost&#281;pnisz znajomym z pracy! Niech te&#380; stan&#261; si&#281; bezpieczniejsi!</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-008-10-03-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://niebezpiecznik.substack.com/p/cyberexpress-008-10-03-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><h2>6. Meta pozywa rejestratora domen</h2><p>Freenom, rejestrator tak &#8220;szacownych&#8221; domen jak .tk w ko&#324;cu dosta&#322; po ty&#322;ku za to, &#380;e olewa&#322; zg&#322;oszenia o nadu&#380;yciach. Pozwa&#322;a go Meta, wstrzyma&#322; rejestracje. <br><a href="https://krebsonsecurity.com/2023/03/sued-by-meta-freenom-halts-domain-registrations">LINK</a><br>A poni&#380;ej ciekawa tabelka pokazuj&#261;ca, kt&#243;re domeny s&#261; najcz&#281;&#347;ciej abusowane:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!R0BL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51ee414-8b95-4ea0-952c-e568070d18ba_617x407.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!R0BL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51ee414-8b95-4ea0-952c-e568070d18ba_617x407.png 424w, https://substackcdn.com/image/fetch/$s_!R0BL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51ee414-8b95-4ea0-952c-e568070d18ba_617x407.png 848w, https://substackcdn.com/image/fetch/$s_!R0BL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51ee414-8b95-4ea0-952c-e568070d18ba_617x407.png 1272w, https://substackcdn.com/image/fetch/$s_!R0BL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51ee414-8b95-4ea0-952c-e568070d18ba_617x407.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!R0BL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51ee414-8b95-4ea0-952c-e568070d18ba_617x407.png" width="617" height="407" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a51ee414-8b95-4ea0-952c-e568070d18ba_617x407.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:407,&quot;width&quot;:617,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!R0BL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51ee414-8b95-4ea0-952c-e568070d18ba_617x407.png 424w, https://substackcdn.com/image/fetch/$s_!R0BL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51ee414-8b95-4ea0-952c-e568070d18ba_617x407.png 848w, https://substackcdn.com/image/fetch/$s_!R0BL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51ee414-8b95-4ea0-952c-e568070d18ba_617x407.png 1272w, https://substackcdn.com/image/fetch/$s_!R0BL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa51ee414-8b95-4ea0-952c-e568070d18ba_617x407.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>7. Kolejne hacki rosyjskich medi&#243;w </h2><p>Zn&#243;w wstrzykni&#281;to fa&#322;szywe komunikaty o atakach bombowych. I dobrze, niech si&#281;&nbsp;spo&#322;ecze&#324;stwo zbrodniarzy wojennych poczuje przez chwil&#281; tak, jak kraj na kt&#243;ry napadli.<br><a href="https://twitter.com/shakirov2036/status/1633826704958566400">LINK</a></p><h2>8. Ukrad&#322;, ale odda&#322;</h2><p>Tender.fi, platforma DeFi zosta&#322;a zhackowana. Go&#347;&#263; ukrad&#322; 1.5 miliona dolar&#243;w, wykorzystuj&#261;c dziur&#281; w kontrakcie, ale potem &#8220;dogada&#322;&#8221; si&#281; z platform&#261;, zwr&#243;ci&#322; pieni&#261;dze i dosta&#322; 96 000 dolar&#243;w jako wynagrodzenie za &#8220;<em>pomoc w zabezpieczeniu platformy przed atakami</em>&#8221; :-D <br><a href="https://twitter.com/tender_fi/status/1633170112718188549">LINK</a></p><h2>9. Za&#322;atajcie sobie HomeAssistanta</h2><p>Bo ma pot&#281;&#380;n&#261; dziur&#281;.<br><a href="https://www.home-assistant.io/blog/2023/03/08/supervisor-security-disclosure">LINK</a></p><h2>10. Raporty</h2><p>Dzi&#347; w k&#261;ciku raportowym:</p><ol><li><p><a href="https://www.dni.gov/index.php/newsroom/reports-publications/reports-publications-2023/item/2363-2023-annual-threat-assessment-of-the-u-s-intelligence-community">Raport ameryka&#324;skiego Wywiadu Narodowego (ODNI)</a> o naprawd&#281; r&#243;&#380;nych zagro&#380;eniach. A jakby kto&#347; chcia&#322; sobie por&#243;wna&#263; poziom dyskusji polityk&#243;w z &#8220;s&#322;u&#380;bami&#8221; w USA a w innych krajach, to tutaj jest te&#380; <a href="https://www.intelligence.senate.gov/hearings/open-hearing-worldwide-threats-3">nagranie</a> (2h50) z prezentacji tego raportu. <br>TL;DR: </p><ul><li><p>USA jest pewne, &#380;e Chiny mog&#261; zhackowa&#263; ich infrastruktur&#281; krytyczn&#261;. </p></li><li><p>Cho&#263; Rosja wy&#322;o&#380;y&#322;a si&#281; je&#347;li chodzi o cyberataki na Ukrain&#281;, to nie mo&#380;na ignorowa&#263; jej zdolno&#347;ci w tym obszarze. Rosjanie maj&#261; te&#380;&nbsp;w kieszeni ameryka&#324;skich polityk&#243;w.</p></li><li><p>ODNI krytykuje ruchy centralizuj&#261;ce bazy z danymi obywateli na temat zdrowia.  Uwa&#380;a, &#380;e to ryzyko. IKP pozdrawia z Polski.</p></li></ul></li><li><p>Dalej USA. Opublikowano <a href="https://www.whitehouse.gov/briefing-room/statements-releases/2023/03/02/fact-sheet-biden-harris-administration-announces-national-cybersecurity-strategy/">Narodow&#261; Strategi&#281; Cyberbezpiecze&#324;stwa</a>. Jednym z postulat&#243;w jest zmuszenie producent&#243;w oprogramowania do wzi&#281;cia odpowiedzialno&#347;ci za szkody, kt&#243;re ich zaniedbania spowoduj&#261;.  Czy to s&#322;uszny kierunek? Zanim skomentujecie, wczytajcie si&#281;&nbsp;w warunki.</p></li><li><p>Dwucz&#281;&#347;ciowy <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/a-noteworthy-threat-how-cybercriminals-are-abusing-onenote-part-2/">opis technik</a> wykorzystywania OneNote&#8217;a do dystrybucji z&#322;o&#347;liwego oprogramowania.</p></li></ol><div><hr></div><h2>* * *</h2><p>Zdali&#347;my sobie spraw&#281;, &#380;e zaniedbywali&#347;my ostatnio obiecan&#261; sekcj&#281; &#347;miesznego obrazka na koniec CyberExpressu. Dlatego tym razem, aby zrekompensowa&#263; niedobory, obrazek b&#281;dzie d&#322;u&#380;szy:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1hJm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79e92561-5c40-4566-b04d-9ce47b608847_1214x811.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1hJm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79e92561-5c40-4566-b04d-9ce47b608847_1214x811.png 424w, https://substackcdn.com/image/fetch/$s_!1hJm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79e92561-5c40-4566-b04d-9ce47b608847_1214x811.png 848w, https://substackcdn.com/image/fetch/$s_!1hJm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79e92561-5c40-4566-b04d-9ce47b608847_1214x811.png 1272w, https://substackcdn.com/image/fetch/$s_!1hJm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79e92561-5c40-4566-b04d-9ce47b608847_1214x811.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1hJm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79e92561-5c40-4566-b04d-9ce47b608847_1214x811.png" width="464" height="309.9703459637562" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79e92561-5c40-4566-b04d-9ce47b608847_1214x811.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:811,&quot;width&quot;:1214,&quot;resizeWidth&quot;:464,&quot;bytes&quot;:319836,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1hJm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79e92561-5c40-4566-b04d-9ce47b608847_1214x811.png 424w, https://substackcdn.com/image/fetch/$s_!1hJm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79e92561-5c40-4566-b04d-9ce47b608847_1214x811.png 848w, https://substackcdn.com/image/fetch/$s_!1hJm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79e92561-5c40-4566-b04d-9ce47b608847_1214x811.png 1272w, https://substackcdn.com/image/fetch/$s_!1hJm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79e92561-5c40-4566-b04d-9ce47b608847_1214x811.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Rozumiecie? D&#322;u&#380;szy! <br>(to by&#322;o &#347;mieszne)</p><p>A co do tego naszego czatu, co go odpalili&#347;my wraz z poprzednim wydaniem CyberExpressu&#8230; S&#322;abo si&#281; ten substackowy czat sprawdza naszym zdaniem, ale damy mu jeszcze jedn&#261; szans&#281;. <a href="https://niebezpiecznik.substack.com/chat">Wy te&#380; spr&#243;bujcie</a>. Jak nie wyjdzie, to za tydzie&#324; odpalimy Discorda. <br><br><em>Bezpiecznego weekendu!<br><br></em>PS. I pom&#243;&#380;cie nam pls z <a href="https://docs.google.com/forms/d/e/1FAIpQLSe9219jeeK-KxjVo1o0uM6yIWzwEpyRrbi04aRj2zQt0S3coA/viewform">t&#261; ankiet&#261; o AI</a>. Dzi&#281;ki!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Przeczyta&#322;e&#347; ca&#322;y &#128642; CyberExpress (newsletter Niebezpiecznika)! Je&#347;li nie otrzymujesz go na swojego maila, to wpisz go poni&#380;ej, a zaczniesz go otrzymywa&#263; na maila :-)</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[CyberExpress #007 (03-03-2023)]]></title><description><![CDATA[W tym wydaniu: nowa technika kradzie&#380;y smartfon&#243;w, gangi zwalniaj&#261;ce haker&#243;w, kompromitacja LastPassa, ataki na T-Mobile, sprytne dzieci i jeszcze sprytniejsze DNS-y. Lektura zajmie ci ok. 3 minuty.]]></description><link>https://niebezpiecznik.substack.com/p/cyberexpress-007-03-03-2023</link><guid isPermaLink="false">https://niebezpiecznik.substack.com/p/cyberexpress-007-03-03-2023</guid><dc:creator><![CDATA[Niebezpiecznik]]></dc:creator><pubDate>Fri, 03 Mar 2023 12:31:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bb542c8-3f73-4af1-a827-ba839f2e9706_1914x2048.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><strong>To wydanie zamiast wst&#281;pniaka b&#281;dzie mia&#322;o kr&#243;tk&#261; list&#281; artyku&#322;&#243;w, kt&#243;re od czasu poprzedniego CyberExpressu pojawi&#322;y si&#281;&nbsp;na Niebezpieczniku. Bo troch&#281; si&#281; dzia&#322;o przez ostatnie dni:</strong></em></p><ul><li><p><em><a href="https://niebezpiecznik.pl/post/pit-uke-punkt-informacyjny-ds-telekomunikacji-mapa/">System UKE stanowi zagro&#380;enie dla bezpiecze&#324;stwa pa&#324;stwa</a> &#8212; tak twierdz&#261; polscy operatorzy, kt&#243;rzy musz&#261; wgra&#263; tam szczeg&#243;&#322;owe plany swoich sieci. Czy maj&#261; racj&#281;? System <strong>pad&#322; po publikacji naszego artyku&#322;u</strong> i dalej le&#380;y&#8230; Niekt&#243;rzy &#380;ycz&#261; mu aby le&#380;a&#322; jak najd&#322;u&#380;ej, bo <a href="https://niebezpiecznik.pl/post/pit-uke-punkt-informacyjny-ds-telekomunikacji-mapa/#comment-886089">od miesi&#261;ca nie mieli przez niego chwili spokoju</a>.</em></p><p></p></li><li><p><em><a href="https://niebezpiecznik.pl/post/jak-probowali-mnie-okrasc-historia-z-booking-com-w-tle/">Jak pr&#243;bowali mnie oszuka&#263; na Bookingu</a> &#8212; relacja jednego z naszych klient&#243;w, <strong>osoby technicznej</strong>, wraz ze szczeg&#243;&#322;owym opisem dlaczego prawie da&#322;a si&#281;&nbsp;podej&#347;&#263;. <br></em></p></li><li><p><em>Opis naszego <a href="https://niebezpiecznik.pl/post/zapraszamy-na-szkolenie-z-bezpieczenstwa-sieci-testow-penetracyjnych/">szkolenia dla admin&#243;w i devops&#243;w</a> - b&#281;dziemy z nim we Wroc&#322;awiu, Warszawie i Krakowie.  <br></em></p></li><li><p><em>Uwaga na ten film, bo <a href="https://niebezpiecznik.pl/post/ten-film-restartuje-smartfony-z-androidem/">restartuje niekt&#243;re smartfony z Androidami</a> <br></em></p></li><li><p><em>Pojawi&#322;o si&#281; narz&#281;dzie do <a href="https://niebezpiecznik.pl/post/wycieklo-ci-nagie-zdjecie-video-do-sieci-  mozesz-je-zablokowac/">usuwania sowich &#8220;niedyskretnych&#8221; zdj&#281;&#263; z sieci</a>. Istnieje ryzyko, &#380;e wykorzystaj&#261; je trole polityczne, do usuwania te&#347;ci z serwis&#243;w internetowych i banowania swoich przeciwnik&#243;w politycznych.<br></em></p></li><li><p><em>Co&#347; dla programist&#243;w: <a href="https://niebezpiecznik.pl/post/github-wprowadzil-secret-scanning-wlaczcie-go-sobie/">w&#322;&#261;czcie t&#281; funkcj&#281; natychmiast</a>, je&#347;li korzystacie z GitHuba</em> </p><p></p></li></ul><div><hr></div><h3>1. &#8220;Nowy i gro&#378;ny&#8221; rodzaj kradzie&#380;y smartfon&#243;w</h3><p>WSJ panikuje, &#380;e jak z&#322;odziej najpierw podejrzy czyje&#347; has&#322;o do iPhona, a potem tego iPhona ukradnie, to b&#281;dzie te&#380; m&#243;g&#322; (bez dodatkowej wiedzy) zmieni&#263; has&#322;o do podpi&#281;tego do tego iPhona konta iCloud. </p><p>Dlaczego Apple nie wymaga podania starego has&#322;a do konta iCloud przed jego zmian&#261;? Bo wiele os&#243;b raz konfiguruje konto na smartfonie, a potem o nim zapomina. I zapomina has&#322;a. A potem jest tragedia kiedy chc&#261; si&#281;&nbsp;do konta zalogowa&#263; (m.in. &#380;eby sprzeda&#263; iPhona lub w&#322;&#261;czy&#263; pewne funkcje).  I takich os&#243;b jest wi&#281;cej ni&#380; tych, kt&#243;rzy trac&#261; smartfona razem z kodem blokady.</p><p><strong>Ciekawostka:</strong> czego &#380;a&#322;uje jedna z ofiar opisywanych przez WSJ? Tego, &#380;e straci&#322;a dost&#281;p do zdj&#281;&#263; bliskich. To pokazuje, &#380;e ofiary naprawd&#281; nie my&#347;l&#261; o bezpiecze&#324;stwie swoich danych, co dopiero o zabezpieczaniu dost&#281;pu do telefonu&#8230; </p><p><strong>Wniosek/Rada:</strong> Nie dajcie sobie wyrywa&#263; odblokowanych iPhon&#243;w z r&#281;ki. A jak ju&#380;&nbsp;Wam kto&#347; takiego wyrwie, to nie krzyczcie za z&#322;odziejem swojego has&#322;a ;)<br><br><strong>Masz Androida</strong> i teraz pod nosem &#347;miejesz si&#281; z iPhoniarzy? To wiedz, &#380;e ten sam problem jest ze smartfonami Androidowymi i kontami Google :D</p><p><a href="https://www.wsj.com/articles/apple-iphone-security-theft-passcode-data-privacya-basic-iphone-feature-helps-criminals-steal-your-digital-life-cbf14b1a">LINK</a></p><div><hr></div><h3>2. &#346;wietny artyku&#322; o SIGINT </h3><p>W kontek&#347;cie przewidywania startu wojny na Ukrainie. D&#322;uga, ale warto&#347;ciowa lektura. </p><p><a href="https://www.politico.com/news/magazine/2023/02/24/russia-ukraine-war-oral-history-00083757">LINK</a></p><div><hr></div><h3>3. Pot&#281;&#380;ny fakap w LastPass pot&#281;&#380;niejszy ni&#380;&nbsp;si&#281; wydawa&#322;o</h3><p>Na jaw wychodz&#261; kolejne k&#322;amstwa/nieczyste zagrywki LastPassa. Firma jawi si&#281; jako coraz bardziej niepowa&#380;na: celowo ukrywa lub op&#243;&#378;nia istotne informacje o ataku kt&#243;ry trwa&#322; od sierpnia 2022. </p><p>Je&#347;li wci&#261;&#380;&nbsp;z LastPassa korzystacie, to chyba najwy&#380;sza pora aby go zast&#261;pi&#263; czym&#347; sensowniejszym (polecamy: KeePass XC lub Bitwarden). </p><ul><li><p><a href="https://arstechnica.com/information-technology/2023/02/lastpass-hackers-infected-employees-home-computer-and-stole-corporate-vault/">Pe&#322;ny opis tego co faktycznie si&#281; sta&#322;o</a> (i jak dosz&#322;o do w&#322;amania)</p></li><li><p><a href="https://support.lastpass.com/download/lastpass-blog-security">O&#347;wiadczenie firmy</a> (kt&#243;re na pocz&#261;tku kr&#261;&#380;y&#322;o tylko w&#347;r&#243;d wybranych klient&#243;w)</p></li><li><p><a href="https://medium.com/@chaim_sanders/its-all-bad-news-an-update-on-how-the-lastpass-breach-affects-lastpass-sso-9b4fa64466f6">Krytyka rekomendacji LastPassa dla klient&#243;w biznesowych</a></p></li></ul><div><hr></div><h3>4. Rz&#261;d USA te&#380; nakazuje odistalowanie TikToka</h3><p>Posz&#322;o lawinowo. W <a href="https://niebezpiecznik.substack.com/i/104830429/komisja-europejska-kaze-pracownikom-odinstalowac-tiktoka-takze-z-prywatnych-urzadzen">poprzednim wydaniu CyberExpressu</a> informowali&#347;my o tym, &#380;e Komisja Europejska zakazuje pracownikom korzystania z TikToka. Teraz to samo robi administracja rz&#261;dowa w USA. Kt&#243;ry kraj b&#281;dzie nast&#281;pny?</p><p><a href="https://www.theregister.com/2023/03/01/government_tiktok_ban/">LINK</a></p><div><hr></div><h3>5. Jak dzieci obchodz&#261; szkolne zakazy korzystania z komunikator&#243;w?</h3><p>Pro&#347;ciutko. Komunikuj&#261; si&#281;&nbsp;przez Googlowego &#8220;PowerPointa&#8221;. Zobaczcie jak wyrafinowany, wspieraj&#261;cy moderacj&#281; tre&#347;ci jest to spos&#243;b:</p><p><a href="https://hcommons.social/@ryancordell/109931704672643355">LINK</a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Czytasz &#128642; CyberExpress, newsletter Niebezpiecznika! Zapisz si&#281;, aby dostawa&#263; kolejne wydania na swojego e-maila:</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h3>6. Tor Project te&#380; walczy z cenzur&#261;</h3><p>Uruchomi&#322; pomoc techniczn&#261;&nbsp;przez WhatsAppa dla os&#243;b, kt&#243;rych rz&#261;dy blokuj&#261; dost&#281;p do Tora. Kto&#347; wie ile rz&#261;d&#243;w blokuje Tora ale nie WhatsAppa?<br><br><a href="https://mastodon.social/@torproject/109920030267450929">LINK</a></p><div><hr></div><h3>7. Google wzmacnia szyfrowanie klientom biznesowym</h3><p>Jesli korzystacie z Google &#8220;dla firm&#8221; to mo&#380;ecie w&#322;&#261;czy&#263; client side encryption. Poni&#380;ej grafika, kt&#243;ra pokazuje, co b&#281;dzie szyfrowane, a co nie. A pod linkiem opis jak to dzia&#322;a i kto oraz jak mo&#380;e to w&#322;&#261;czy&#263;. <br><br><a href="https://workspace.google.com/blog/product-announcements/gmail-and-calendar-client-side-encryption">LINK</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8m-G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecf04e44-bb0a-4e13-9e54-d438fd400abb_2342x1698.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8m-G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecf04e44-bb0a-4e13-9e54-d438fd400abb_2342x1698.png 424w, https://substackcdn.com/image/fetch/$s_!8m-G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecf04e44-bb0a-4e13-9e54-d438fd400abb_2342x1698.png 848w, https://substackcdn.com/image/fetch/$s_!8m-G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecf04e44-bb0a-4e13-9e54-d438fd400abb_2342x1698.png 1272w, https://substackcdn.com/image/fetch/$s_!8m-G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecf04e44-bb0a-4e13-9e54-d438fd400abb_2342x1698.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8m-G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecf04e44-bb0a-4e13-9e54-d438fd400abb_2342x1698.png" width="1456" height="1056" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ecf04e44-bb0a-4e13-9e54-d438fd400abb_2342x1698.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1056,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:405307,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8m-G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecf04e44-bb0a-4e13-9e54-d438fd400abb_2342x1698.png 424w, https://substackcdn.com/image/fetch/$s_!8m-G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecf04e44-bb0a-4e13-9e54-d438fd400abb_2342x1698.png 848w, https://substackcdn.com/image/fetch/$s_!8m-G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecf04e44-bb0a-4e13-9e54-d438fd400abb_2342x1698.png 1272w, https://substackcdn.com/image/fetch/$s_!8m-G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fecf04e44-bb0a-4e13-9e54-d438fd400abb_2342x1698.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#378;r&#243;d&#322;o: https://arstechnica.com/information-technology/2023/02/google-adds-client-side-encryption-to-gmail-and-calendar-should-you-care/</figcaption></figure></div><div><hr></div><h3>8. &#8220;Gangi zwalniaj&#261; haker&#243;w&#8221;</h3><p>Bzdurny artyku&#322; z BusinessInsidera sugeruje, &#380;e zwalniani s&#261; hakerzy. Ale w rzeczywisto&#347;ci chodzi o to, &#380;e niekt&#243;re grupy ransomware&#8217;owe zwalniaj&#261; operator&#243;w ze swoich Call Center. Ale to &#380;adni &#8220;hakerzy&#8221;&#8230;<br><br><a href="https://www.businessinsider.com/hackers-ransomware-getting-laid-off-amid-better-cybersecurity-report-2023-2?r=US&amp;IR=T">LINK</a></p><div><hr></div><h3>9. Cudowna prezentacja o hakowaniu DNS-a</h3><p>Polecamy gor&#261;co. Zdziwicie si&#281;&nbsp;do czego mo&#380;na wykorzysta&#263; ten protok&#243;&#322;. I nie chodzi tylko o tunelowanie innego ruchu w ramach pakiet&#243;w DNS.</p><p><a href="https://fosdem.org/2023/schedule/event/dns_bizarre_and_unusual_uses_of_dns/">LINK</a></p><div><hr></div><h3>10. T-Mobile dojechane 100 razy. Telefonami &#8220;na pracownika dzia&#322;u IT&#8221;</h3><p>Brian Krebas opisuje jak r&#243;&#380;ne grupy vishuj&#261; pracownik&#243;w T-Mobile w USA, aby poprzez przechwycone dost&#281;py wyrabia&#263; duplikaty kart SIM (i okrada&#263; ich w&#322;a&#347;cicieli).</p><p><a href="https://krebsonsecurity.com/2023/02/hackers-claim-they-breached-t-mobile-more-than-100-times-in-2022/">LINK</a></p><div><hr></div><h3>&#128104;&#8205;&#127979; Raporty</h3><p>W tym tygodniu w sekcji raport&#243;w na&#347;wietlamy tylko jeden, dotycz&#261;cy <a href="https://email.protenus.com/hubfs/Breach_Barometer/2023/BreachBarometer_Privacy_2023_Protenus.pdf">cyberbezpiecze&#324;stwa bran&#380;y medycznej</a> (niestety, tylko w USA, ale z naszego do&#347;wiadczenia wiele wniosk&#243;w i problem&#243;w w Polsce jest to&#380;samych)</p><div><hr></div><p>Dzi&#347; zamiast &#347;miesznego obrazka, co&#347; nostalgicznego. Obudowa na dysk przeno&#347;ny przypominaj&#261;ca dyskietk&#281;, ale z interaktywnym wy&#347;wietlaczem! Tu <a href="https://t.co/uLITEPYxRL">instrukcja</a> do samodzielnego zbudowania.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vIN3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bb542c8-3f73-4af1-a827-ba839f2e9706_1914x2048.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vIN3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bb542c8-3f73-4af1-a827-ba839f2e9706_1914x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vIN3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bb542c8-3f73-4af1-a827-ba839f2e9706_1914x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vIN3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bb542c8-3f73-4af1-a827-ba839f2e9706_1914x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vIN3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bb542c8-3f73-4af1-a827-ba839f2e9706_1914x2048.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vIN3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bb542c8-3f73-4af1-a827-ba839f2e9706_1914x2048.jpeg" width="217" height="232.20192307692307" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9bb542c8-3f73-4af1-a827-ba839f2e9706_1914x2048.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1558,&quot;width&quot;:1456,&quot;resizeWidth&quot;:217,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vIN3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bb542c8-3f73-4af1-a827-ba839f2e9706_1914x2048.jpeg 424w, https://substackcdn.com/image/fetch/$s_!vIN3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bb542c8-3f73-4af1-a827-ba839f2e9706_1914x2048.jpeg 848w, https://substackcdn.com/image/fetch/$s_!vIN3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bb542c8-3f73-4af1-a827-ba839f2e9706_1914x2048.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!vIN3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bb542c8-3f73-4af1-a827-ba839f2e9706_1914x2048.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h1>* * *</h1><p><em>Z ostatniej ankiety wynika, &#380;e 64% os&#243;b chcia&#322;o by w&#322;&#261;czy&#263; czat. No to czat w&#322;&#261;czyli&#347;my :)  Tu mo&#380;ecie do&#322;&#261;czy&#263;:</em></p><div class="community-chat" data-attrs="{&quot;url&quot;:&quot;https://open.substack.com/pub/niebezpiecznik/chat?utm_source=chat_embed&quot;,&quot;subdomain&quot;:&quot;niebezpiecznik&quot;,&quot;pub&quot;:{&quot;id&quot;:1188427,&quot;name&quot;:&quot;&#128642; CyberExpress (newsletter Niebezpiecznika)&quot;,&quot;author_name&quot;:&quot;Niebezpiecznik&quot;,&quot;author_photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F32fbc06a-5a4f-4ca6-a07f-e561b8895dec_144x144.png&quot;}}" data-component-name="CommunityChatRenderPlaceholder"></div><p><em>Ten czat dzia&#322;a tylko je&#347;li kto&#347; ma <strong><a href="https://substack.com/app">aplikacj&#281; mobiln&#261; Substacka</a></strong> (o czym by&#263; mo&#380;e powinni&#347;my wspomnie&#263; w poprzedniej ankiecie&#8230;). No nic, zobaczmy jak to si&#281; przyjmie. Z ostatniej ankiety wynika, &#380;e a&#380; 31% os&#243;b ma apetyt na Discorda, wi&#281;c jak substackowy chat nie si&#261;dzie, to odpalimy Discorda.  </em></p><p><em>Po odpaleniu apki czat znajdziecie tutaj:</em></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2H2-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a23d49f-76bd-4f75-baac-0ae5733774bd_1456x743.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2H2-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a23d49f-76bd-4f75-baac-0ae5733774bd_1456x743.png 424w, https://substackcdn.com/image/fetch/$s_!2H2-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a23d49f-76bd-4f75-baac-0ae5733774bd_1456x743.png 848w, https://substackcdn.com/image/fetch/$s_!2H2-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a23d49f-76bd-4f75-baac-0ae5733774bd_1456x743.png 1272w, https://substackcdn.com/image/fetch/$s_!2H2-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a23d49f-76bd-4f75-baac-0ae5733774bd_1456x743.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2H2-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a23d49f-76bd-4f75-baac-0ae5733774bd_1456x743.png" width="359" height="183.19848901098902" data-attrs="{&quot;src&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/9a23d49f-76bd-4f75-baac-0ae5733774bd_1456x743.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:743,&quot;width&quot;:1456,&quot;resizeWidth&quot;:359,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2H2-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a23d49f-76bd-4f75-baac-0ae5733774bd_1456x743.png 424w, https://substackcdn.com/image/fetch/$s_!2H2-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a23d49f-76bd-4f75-baac-0ae5733774bd_1456x743.png 848w, https://substackcdn.com/image/fetch/$s_!2H2-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a23d49f-76bd-4f75-baac-0ae5733774bd_1456x743.png 1272w, https://substackcdn.com/image/fetch/$s_!2H2-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F9a23d49f-76bd-4f75-baac-0ae5733774bd_1456x743.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><blockquote><p><em>Pami&#281;tajcie te&#380;, &#380;e je&#347;li chciecie co&#347;&nbsp;skomentowa&#263;, to mo&#380;ecie to tak&#380;e zrobi&#263; publicznie, zostawiaj&#261;c komentarz pod tym newsletterem albo prywatnie, po prostu odpisuj&#261;c do nas. </em></p></blockquote><p><em>PS. My&#347;limy jak zebra&#263; od Was feedback co do tego, kt&#243;re linki z danego wydania newslettera uwa&#380;acie za najbardziej przydatne. To pozwoli nam odpowiednio zwi&#281;kszy&#263; wag&#281; danym tre&#347;ciom. Kto&#347;&nbsp;ma pomys&#322; jak to ogarn&#261;&#263;? </em></p><p></p><p> </p><p></p>]]></content:encoded></item><item><title><![CDATA[CyberExpress #006 (24-02-2023) ]]></title><description><![CDATA[Dzi&#347;: rady od NSA, omijanie biometrii, banowanie oszust&#243;w, wycieki, exploity, zhackowani Rosjanie i policjanci. Lektura zajmie Ci ~3 minuty. Chyba, &#380;e tylko nag&#322;&#243;wki scrollujesz, &#322;achudro! To mniej.]]></description><link>https://niebezpiecznik.substack.com/p/cyberexpress-006-24-02-2023</link><guid isPermaLink="false">https://niebezpiecznik.substack.com/p/cyberexpress-006-24-02-2023</guid><dc:creator><![CDATA[Piotr Konieczny 👾]]></dc:creator><pubDate>Fri, 24 Feb 2023 13:23:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rka5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcd4abae-0b8b-49bf-8e9b-815f45faead8_1440x961.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><strong>Dzi&#347; zamiast wst&#281;pniaka kr&#243;tka pro&#347;ba. </strong></em></p><p><em><strong>Planujemy webinar o Sztucznej Inteligencji (tym jak sprytnie j&#261; wykorzysta&#263; do u&#322;atwienia sobie &#380;ycia i pracy; tym na co uwa&#380;a&#263;) &#8212; z ch&#281;ci&#261; poruszymy zagadnienia z tego obszaru, kt&#243;re Was interesuj&#261;, dlatego prosimy: <a href="https://docs.google.com/forms/d/e/1FAIpQLSe9219jeeK-KxjVo1o0uM6yIWzwEpyRrbi04aRj2zQt0S3coA/viewform">odpowiedzcie na te 3 pytania</a>. Nie zajmie to wi&#281;cej ni&#380; minuty. Dzi&#281;ki!</strong></em></p><div><hr></div><h3>1. Biometria g&#322;osowa w banku zhackowana</h3><p>Stosowanie biometrii g&#322;osowej do uwierzytelnienia <strong>to pomy&#322;ka</strong>. <a href="https://niebezpiecznik.pl/post/identyfikacja-polakow-po-glosie-czyli-nowy-system-w-fiskusie-i-bz-wbk/">W Niebezpieczniku zwracali&#347;my na to uwag&#281;  ju&#380; w 2015 roku</a>. A teraz dziennikarz skorzysta&#322; z publicznie dost&#281;pnego narz&#281;dzia AI do fa&#322;szowania g&#322;osu i tak wygenerowan&#261; pr&#243;bk&#261; obszed&#322; zabezpieczenia w banku.</p><p><a href="https://www.vice.com/en/article/dy7axa/how-i-broke-into-a-bank-account-with-an-ai-generated-voice">https://www.vice.com/en/article/dy7axa/how-i-broke-into-a-bank-account-with-an-ai-generated-voice</a></p><div><hr></div><h3>2. NSA opracowa&#322;o rady dla pracownik&#243;w zdalnych</h3><p>Materia&#322; do&#347;&#263; kr&#243;tki, a kilka rad &#8220;chroni&#8221;&nbsp;przed ma&#322;o prawdopodobnymi zagro&#380;eniami. Ale zapozna&#263; si&#281; warto.</p><p><a href="https://media.defense.gov/2023/Feb/22/2003165170/-1/-1/0/CSI_BEST_PRACTICES_FOR_SECURING_YOUR_HOME_NETWORK.PDF">https://media.defense.gov/2023/Feb/22/2003165170/-1/-1/0/CSI_BEST_PRACTICES_FOR_SECURING_YOUR_HOME_NETWORK.PDF</a><br></p><blockquote><pre><code>&#9888;&#65039; Je&#347;li szukacie materia&#322;u, kt&#243;ry kompleksowo podpowiada na co zwr&#243;ci&#263; uwag&#281; podczas pracy zdalnej, je&#347;li chodzi o bezpiecze&#324;stwo, zar&#243;wno od strony pracownika jak i pracodawcy, to polecamy obejrzenie <a href="https://sklep.niebezpiecznik.pl/opis/3">nagrania naszego webinaru</a>. Z kodem &#8220;CYBEREXPRESS&#8221; dost&#281;p uzyskacie a&#380;&nbsp;o 99 PLN taniej. Kod b&#281;dzie aktywny <strong>tylko do ko&#324;ca dnia</strong>, ale dost&#281;p przydzielamy na 30 dni, wi&#281;c na pewno zd&#261;&#380;ycie obejrze&#263;. &#9888;&#65039;</code></pre></blockquote><h3></h3><div><hr></div><h3>3. Komisja Europejska ka&#380;e pracownikom odinstalowa&#263; TikToka, tak&#380;e z prywatnych urz&#261;dze&#324;</h3><p>Je&#347;li kto&#347;&nbsp;tego nie zrobi, niebawem straci dost&#281;p do s&#322;u&#380;bowej poczty i komunikatora (Skype for Business). Podobne zakazy ju&#380; jaki&#347; czas temu wprowadzi&#322;a administracja w USA. Powodem tej decyzji jest obawa o bezpiecze&#324;stwo danych os&#243;b, kt&#243;re korzystaj&#261; z TikToka, cho&#263; my dodaliby&#347;my, &#380;e tak&#380;e o rozum i godno&#347;&#263; cz&#322;owieka.</p><p><a href="https://www.bbc.com/news/technology-64743991">https://www.bbc.com/news/technology-64743991</a></p><p>Na marginesie: zamyka si&#281; polskie biuro TikToka.</p><div><hr></div><h3>4. Jest zdj&#281;cie chi&#324;skiego balona szpiegowskiego!</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rka5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcd4abae-0b8b-49bf-8e9b-815f45faead8_1440x961.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rka5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcd4abae-0b8b-49bf-8e9b-815f45faead8_1440x961.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rka5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcd4abae-0b8b-49bf-8e9b-815f45faead8_1440x961.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rka5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcd4abae-0b8b-49bf-8e9b-815f45faead8_1440x961.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rka5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcd4abae-0b8b-49bf-8e9b-815f45faead8_1440x961.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rka5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcd4abae-0b8b-49bf-8e9b-815f45faead8_1440x961.jpeg" width="1440" height="961" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dcd4abae-0b8b-49bf-8e9b-815f45faead8_1440x961.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:961,&quot;width&quot;:1440,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rka5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcd4abae-0b8b-49bf-8e9b-815f45faead8_1440x961.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rka5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcd4abae-0b8b-49bf-8e9b-815f45faead8_1440x961.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rka5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcd4abae-0b8b-49bf-8e9b-815f45faead8_1440x961.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rka5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcd4abae-0b8b-49bf-8e9b-815f45faead8_1440x961.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Ujawniono fotk&#281; zrobion&#261; przez pilota U-2S Dragon Fly (kt&#243;rego cie&#324; wida&#263; na balonie). The War Zone zrobi&#322; zoom&amp;enhance i przeanalizowa&#322; &#322;adunek przenoszony przez balon:</p><p><a href="https://www.thedrive.com/the-war-zone/our-best-look-yet-at-the-chinese-spy-balloons-massive-payload">https://www.thedrive.com/the-war-zone/our-best-look-yet-at-the-chinese-spy-balloons-massive-payload</a></p><p>A bra&#263; OSINT-owa namierzy&#322;a miejsce wykonania zdj&#281;cia na podstawie rze&#378;by terenu:</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/obretix/status/1628511189582942209&quot;,&quot;full_text&quot;:&quot;some 100km west of St. Louis <a class=\&quot;tweet-url\&quot; href=\&quot;https://earth.google.com/web/@39.1883119,-91.05477019,230.14295324a,80095.87365579d,35y,52.1545222h,71.25308458t,0r\&quot;>earth.google.com/web/@39.188311&#8230;</a> a place called Bellflower in the lower left corner there <a class=\&quot;tweet-url\&quot; href=\&quot;https://www.dvidshub.net/image/7644960\&quot;>dvidshub.net/image/7644960</a>  &quot;,&quot;username&quot;:&quot;obretix&quot;,&quot;name&quot;:&quot;Samir&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Wed Feb 22 21:44:58 +0000 2023&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://pbs.substack.com/media/FpmiHbBXEAE4_QH.jpg&quot;,&quot;link_url&quot;:&quot;https://t.co/MNrpxtpLtl&quot;,&quot;alt_text&quot;:null},{&quot;img_url&quot;:&quot;https://pbs.substack.com/media/FpmiH0GWIAQ2b75.jpg&quot;,&quot;link_url&quot;:&quot;https://t.co/MNrpxtpLtl&quot;,&quot;alt_text&quot;:null}],&quot;quoted_tweet&quot;:{&quot;full_text&quot;:&quot;&#128248;: The Pentagon has provided &amp;amp; confirmed authenticity of this selfie taken by a U-2 pilot flying by the Chinese surveillance balloon.\n\nCNN reported earlier this month that the photo had reached legendary status in the Pentagon and NORAD. https://t.co/BWRiSxADSO&quot;,&quot;username&quot;:&quot;halbritz&quot;,&quot;name&quot;:&quot;Haley Britzky&quot;},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:190,&quot;like_count&quot;:1157,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><div><hr></div><h3>5. Valve zastawi&#322;o pu&#322;apk&#281; i zbanowa&#322;o 40 000 graczy</h3><p>A raczej oszust&#243;w, kt&#243;rzy cheatowali w Dota2&#8230; Valve wypu&#347;ci&#322;o patcha-honeypota. Pod&#322;o&#380;yli dane w takim miejscu, jakie podczas normalnej rozgrywki nigdy nie jest odczytywane, ale jakie zostanie odczytane, je&#347;li kto&#347; korzysta z exploita (cheata). <br><br><a href="https://www.dota2.com/newsentry/3677788723152833273">https://www.dota2.com/newsentry/3677788723152833273</a></p><div><hr></div><h3>6. Wyciek&#322;y dane os&#243;b robi&#261;cych testy DNA</h3><p>Firma DNA Diagnostics Center zajmuj&#261;ca si&#281; testami DNA zosta&#322;a zhackowana. W&#322;amywacze wykradli dane ponad 2 milion&#243;w os&#243;b. Dane mia&#322;y pochodzi&#263; z &#8220;zapomnianej&#8221; bazy, a firma mog&#322;a unikn&#261;&#263; ich wycieku, bo zosta&#322;a powiadomiona du&#380;o wcze&#347;niej, &#380;e w jej sieci dzieje si&#281; co&#347; niedobrego. Ale nie zareagowa&#322;a. </p><p>No c&#243;&#380;, w takiej sytuacji rekomendujemy poszkodowanym zmian&#281; swojego DNA na nowe. A nie, czekaj&#8230;</p><p><a href="https://gizmodo.com/dna-testing-diagnostics-center-leaked-data-forgot-1850140233">https://gizmodo.com/dna-testing-diagnostics-center-leaked-data-forgot-1850140233</a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Czytasz &#128642; CyberExpress, newsletter Niebezpiecznika! Zapisz si&#281;, aby dostawa&#263; kolejne wydania na swojego e-maila:</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h3>7. Exploit na Fortineta wykorzystywany do atak&#243;w</h3><p>W 4 wydaniu CyberExpressu <a href="https://niebezpiecznik.substack.com/i/103850856/dziury-w-urzadzeniach-fortinet">pisali&#347;my o dziurach w urz&#261;dzeniach Fortinet</a> i zach&#281;cali&#347;my do ich patchowania. Je&#347;li nas nie pos&#322;uchali&#347;cie, to teraz macie problem, bo exploit zosta&#322; upubliczniony i ju&#380; jest aktywnie wykorzystywany do atak&#243;w.</p><p><a href="https://www.horizon3.ai/fortinet-fortinac-cve-2022-39952-deep-dive-and-iocs/">https://www.horizon3.ai/fortinet-fortinac-cve-2022-39952-deep-dive-and-iocs/</a></p><div><hr></div><h3>8. Magiczna gumka od Google usunie niechciane osoby ze zdj&#281;cia</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vO30!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424e8fc4-684b-4db0-8959-18d14209b6b5_1000x563.bin" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vO30!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424e8fc4-684b-4db0-8959-18d14209b6b5_1000x563.bin 424w, https://substackcdn.com/image/fetch/$s_!vO30!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424e8fc4-684b-4db0-8959-18d14209b6b5_1000x563.bin 848w, https://substackcdn.com/image/fetch/$s_!vO30!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424e8fc4-684b-4db0-8959-18d14209b6b5_1000x563.bin 1272w, https://substackcdn.com/image/fetch/$s_!vO30!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424e8fc4-684b-4db0-8959-18d14209b6b5_1000x563.bin 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vO30!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424e8fc4-684b-4db0-8959-18d14209b6b5_1000x563.bin" width="1000" height="563" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/424e8fc4-684b-4db0-8959-18d14209b6b5_1000x563.bin&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:563,&quot;width&quot;:1000,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Three images showing the steps of using Magic Eraser in Google Photos.&quot;,&quot;title&quot;:&quot;Three images showing the steps of using Magic Eraser in Google Photos.&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Three images showing the steps of using Magic Eraser in Google Photos." title="Three images showing the steps of using Magic Eraser in Google Photos." srcset="https://substackcdn.com/image/fetch/$s_!vO30!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424e8fc4-684b-4db0-8959-18d14209b6b5_1000x563.bin 424w, https://substackcdn.com/image/fetch/$s_!vO30!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424e8fc4-684b-4db0-8959-18d14209b6b5_1000x563.bin 848w, https://substackcdn.com/image/fetch/$s_!vO30!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424e8fc4-684b-4db0-8959-18d14209b6b5_1000x563.bin 1272w, https://substackcdn.com/image/fetch/$s_!vO30!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F424e8fc4-684b-4db0-8959-18d14209b6b5_1000x563.bin 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Ju&#380; nie trzeba b&#281;dzie uczy&#263; si&#281; Photoshopa, &#380;eby kogo&#347; usun&#261;&#263; ze zdj&#281;cia! </p><p><a href="https://blog.google/products/photos/magic-eraser-android-ios-google-one/">https://blog.google/products/photos/magic-eraser-android-ios-google-one/</a></p><div><hr></div><h3>9. Kopa&#322; kryptowaluty w szkole</h3><p>Kolejna historia cz&#322;owieka, kt&#243;ry krad&#322; pr&#261;d pod swoj&#261; farm&#281; koparek kryptowalutowych. Tym razem schowa&#322; je w szkole, za &#347;cian&#261; z ta&#347;my klej&#261;cej&#8230; </p><p><a href="https://apnews.com/article/massachusetts-c59f30e1736c7409e41357f1ae2e7b93">https://apnews.com/article/massachusetts-c59f30e1736c7409e41357f1ae2e7b93</a></p><div><hr></div><h3>10. Policjant wys&#322;a&#322; s&#322;u&#380;bowe pliki na prywatn&#261; skrzynk&#281;</h3><p>Jeden policjant wys&#322;a&#322; temu drugiemu policjantowi s&#322;u&#380;bowe dane dotycz&#261;ce zabezpieczenia wizyty Bidena na prywatn&#261; skrzynk&#281;. Wszyscy opisuj&#261; ten incydent w charakterze skandalu i &#347;miej&#261; si&#281; z policji. A my tym razem na przek&#243;r innym napiszemy: <strong>brawa dla tych funkcjonariuszy (lub cywil&#243;w) z IT KGP</strong>, kt&#243;rzy ten wyciek wykryli. To pokazuje, &#380;e kto&#347; tam tego ich LOTUS-a jednak monitoruje. I dobrze.<br><br><a href="https://wiadomosci.radiozet.pl/polska/dokumenty-z-zabezpieczenia-wizyty-bidena-na-prywatnej-skrzynce-policjanta-z-ochoty">https://wiadomosci.radiozet.pl/polska/dokumenty-z-zabezpieczenia-wizyty-bidena-na-prywatnej-skrzynce-policjanta-z-ochoty</a></p><p><em>PS. Kto wie, dlaczego ten temat umie&#347;cili&#347;my za poprzednim? ;P Odpiszcie mailowo. Dla 3 pierwszych os&#243;b, kt&#243;re udziel&#261; poprawnych odpowiedzi, pode&#347;lemy <a href="https://gadzety.niebezpiecznik.pl">niebezpieczne ga&#380;ety</a> :)</em></p><div><hr></div><h3>11. Ruskie radiostacje zhackowane</h3><p>Kto&#347; nada&#322; fa&#322;szywy komunikat alarmu bombowego i spowodowa&#322; &#380;e Rosjanie ruszyli do schron&#243;w. I bardzo dobrze, niech poczuj&#261; na sobie terror, jaki ich kraj stosuje przeciwko innym.  </p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/niebezpiecznik/status/1628499397213290499&quot;,&quot;full_text&quot;:&quot;Ioioioio &#128227; &quot;,&quot;username&quot;:&quot;niebezpiecznik&quot;,&quot;name&quot;:&quot;Niebezpiecznik&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Wed Feb 22 20:58:07 +0000 2023&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{&quot;full_text&quot;:&quot;Today, radio stations across Russia including in  Volgograd, Stavropol, Moscow region broadcasted air raid warnings (the video is reportedly from Belgorod)\n\nAcc to the Ministry of Emergency Situations this messages is fake and was caused by a hacker attack https://t.co/Cd7bGeVVAx https://t.co/wfuIjGQkyZ&quot;,&quot;username&quot;:&quot;shakirov2036&quot;,&quot;name&quot;:&quot;Oleg Shakirov&quot;},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:2,&quot;like_count&quot;:58,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><div><hr></div><h3>12. Raporty</h3><p>Tym razem, ze wzgl&#281;du na dzisiejsz&#261; rocznic&#281;, polecamy <a href="https://cert.europa.eu/static/MEMO/2023/TLP-CLEAR-CERT-EU-1YUA-CyberOps.pdf">podsumowanie roku cyberoperacji zwi&#261;zanych z wojn&#261; w Ukrainie</a> od CERT Europa. I pozostaj&#261;c w temacie, zacytujmy (bardzo odkrywczy :D) <a href="https://therecord.media/dutch-intelligence-russia-cyberattacks-many-not-yet-public-knowledge/">wniosek</a> Holendr&#243;w, &#380;e &#8220;nie wszystkie ataki Rosjan s&#261; znane opinii publicznej&#8230;&#8221; &#128580; <br><br>A jak komu&#347; ma&#322;o analiz &#8220;cyberwojennych&#8221; to tu kolejna <a href="https://www.aspeninstitute.org/publications/the-cyber-defense-assistance-imperative-lessons-from-ukraine/">analiza</a>, od Aspen Institute. </p><div><hr></div><h2>* * * </h2><p>Tyle na dzisiaj. Tym razem ankiety nie b&#281;dzie, bo wci&#261;&#380;&nbsp;aktywna jest ankieta z poprzedniego wydania CyberExpressu. Niewiele os&#243;b odda&#322;o g&#322;os, wi&#281;c zach&#281;camy do <a href="https://niebezpiecznik.substack.com/i/104402277/">klikni&#281;cia tu, przescrollowania i zag&#322;osowania</a>! Inaczej inni wybior&#261; za Was ;P</p><p><em>Bezpiecznego weekendu!<br>&#1057;&#1083;&#1072;&#1074;&#1072; &#1059;&#1082;&#1088;&#1072;&#1111;&#1085;&#1110;!</em></p>]]></content:encoded></item><item><title><![CDATA[CyberExpress #005 (22-02-2023)]]></title><description><![CDATA[W tym wydaniu: z&#322;o&#347;liwe dodatki do Chrome, troch&#281; OSINT-u, opisy atak&#243;w na kilka firm i kompromitacja rosyjskich rz&#261;dowych haker&#243;w. Lektura zajmie Ci ~3 minuty.]]></description><link>https://niebezpiecznik.substack.com/p/cyberexpress-005-22-02-2023</link><guid isPermaLink="false">https://niebezpiecznik.substack.com/p/cyberexpress-005-22-02-2023</guid><pubDate>Wed, 22 Feb 2023 10:31:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Zeb_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7c682b5-1413-47ff-9a7f-a454131c910a_693x493.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Zanim przejdziemy do dzisiejszych cyberekspres&#243;w, dwie kr&#243;tkie, ale istotne informacje. </em></p><ol><li><p><em>Przekroczyli&#347;my pr&#243;g 5000 sybskrybent&#243;w tego newslettera &#127881; , ale &#8220;wej&#347;&#263;&#8221; i odczyt&#243;w mamy o kilka tysi&#281;cy wi&#281;cej&#8230; &#129300; To oznacza, &#380;e wielu z Was czyta, ale nie jest zapisanych. Mo&#380;ecie to zmieni&#263; klikaj&#261;c na przycisk poni&#380;ej ;) <br></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://niebezpiecznik.substack.com/subscribe?"><span>Subscribe now</span></a></p><p><em>To te&#380; dobra okazja, aby podzi&#281;kowa&#263; Wam za dzielenie si&#281; linkiem do newslettera na firmowych Slackach. Uwielbiamy Wasze screeny z reakcjami Waszych kole&#380;anek i koleg&#243;w z pracy na poszczeg&#243;lne linki i fragmenty z newslettera jakie nam wysy&#322;acie na priv.</em> <br></p></li><li><p><em>Informacja w poprzednim wydaniu dotycz&#261;ca mo&#380;liwo&#347;ci <a href="https://niebezpiecznik.pl/post/wez-udzial-w-szkoleniach-niebezpiecznika-calkowicie-za-darmo/">darmowego udzia&#322;u w naszych szkoleniach</a> zddosowa&#322;a zala&#322;a nas lawin&#261; pyta&#324;. Robimy co mo&#380;emy, aby na nie szybko i rzeczowo odpowiada&#263;. Ale je&#347;li potrzebujecie <strong>b&#322;yskawicznej pomocy w wype&#322;nieniu wniosku</strong>, bo deadline w Waszym mie&#347;cie to dzi&#347; lub jutro, to sugerujemy kontakt telefoniczny z naszym biurem: 12-44-202-44. <br></em></p></li></ol><div><hr></div><h3>1. Powsta&#322;o szpiegowskie rozszerzenie do Chroma</h3><p>Wykrada wszystko, wnioskuje o ka&#380;de uprawnienie, robi najgorsze mo&#380;liwe rzeczy, na jakie pozwala API rozszerze&#324; do przegl&#261;darki. Ciasteczka, historia, zrzut ekranu, naciskane klawisze, zawarto&#347;&#263; schowka. Oczywi&#347;cie w celach edukacyjnych. &#379;eby&#347;cie wiedzieli, co Wam grozi je&#347;li kt&#243;re&#347; z wykorzystywanych przez Was rozszerze&#324; si&#281; zbuntuje lub zostanie zhackowane. Opis tworzenia dodatku poni&#380;ej:</p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:104158781,&quot;url&quot;:&quot;https://mattfrisbie.substack.com/p/spy-chrome-extension&quot;,&quot;publication_id&quot;:1430353,&quot;publication_name&quot;:&quot;Building Browser Extensions&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f89e3a2-f508-4b93-a084-a126ba50c6f3_998x998.png&quot;,&quot;title&quot;:&quot;Let's build a Chrome extension that steals everything&quot;,&quot;truncated_body_text&quot;:&quot;Manifest v3 may have taken some of the juice out of browser extensions, but I think there is still plenty left in the tank. To prove it, let&#8217;s build a Chrome extension that steals as much data as possible. I&#8217;m talking kitchen sink, whole enchilada, Grinch-plundering-Whoville levels of data theft.&quot;,&quot;date&quot;:&quot;2023-02-21T20:06:23.174Z&quot;,&quot;like_count&quot;:12,&quot;comment_count&quot;:4,&quot;bylines&quot;:[{&quot;id&quot;:28235054,&quot;name&quot;:&quot;Matt Frisbie&quot;,&quot;previous_name&quot;:&quot;Jhezskc&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/847d32f2-7239-43ac-bab0-57a54523090d_600x941.jpeg&quot;,&quot;bio&quot;:&quot;Software engineer, author of http://buildingbrowserextensions.com - available now!&quot;,&quot;profile_set_up_at&quot;:&quot;2023-02-19T04:18:22.734Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:1393567,&quot;user_id&quot;:28235054,&quot;publication_id&quot;:1430353,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:false,&quot;publication&quot;:{&quot;id&quot;:1430353,&quot;name&quot;:&quot;Building Browser Extensions&quot;,&quot;subdomain&quot;:&quot;mattfrisbie&quot;,&quot;custom_domain&quot;:null,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Building Browser Extensions is the ultimate guide for how to build modern Chrome extensions in 2023 with in-depth examples and detailed tutorials.\n\nhttps://buildingbrowserextensions.com&quot;,&quot;logo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0f89e3a2-f508-4b93-a084-a126ba50c6f3_998x998.png&quot;,&quot;author_id&quot;:28235054,&quot;theme_var_background_pop&quot;:&quot;#99A2F1&quot;,&quot;created_at&quot;:&quot;2023-02-19T04:18:50.032Z&quot;,&quot;rss_website_url&quot;:null,&quot;email_from_name&quot;:null,&quot;copyright&quot;:&quot;Matt Frisbie&quot;,&quot;founding_plan_name&quot;:null,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;}}],&quot;twitter_screen_name&quot;:&quot;mattfriz&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;inviteAccepted&quot;:true}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://mattfrisbie.substack.com/p/spy-chrome-extension?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!MnBo!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0f89e3a2-f508-4b93-a084-a126ba50c6f3_998x998.png" loading="lazy"><span class="embedded-post-publication-name">Building Browser Extensions</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">Let's build a Chrome extension that steals everything</div></div><div class="embedded-post-body">Manifest v3 may have taken some of the juice out of browser extensions, but I think there is still plenty left in the tank. To prove it, let&#8217;s build a Chrome extension that steals as much data as possible. I&#8217;m talking kitchen sink, whole enchilada, Grinch-plundering-Whoville levels of data theft&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">3 years ago &#183; 12 likes &#183; 4 comments &#183; Matt Frisbie</div></a></div><div><hr></div><h3>2. Jak na podstawie numeru telefonu ustali&#263; czyje&#347; inne dane?</h3><p>Kr&#243;tkie <a href="https://static.maltego.com/cdn/Case%20studies/Maltego_Case_Study_Investigating_Alleged_Leak_FSB_Agent_Phone_Numbers.pdf">case study</a> od Maltego bazuj&#261;ce na pluginie ShadowDragon SocialNet. <br></p><blockquote><p><em><strong>A jak to robi&#263; z polskimi numerami? Kilka trik&#243;w pokazali&#347;my na  darmowym webinarze po&#347;wi&#281;conym OSINT-owi<a href="https://niebezpiecznik.pl/live-osint/"> (tu zobaczysz jego nagranie)</a>. Webinar ujawnia tylko cz&#281;&#347;&#263; technik i narz&#281;dzi, kt&#243;re pokazujemy w ramach naszego szkolenia &#8220;<a href="https://niebezpiecznik.pl/post/osint-bialy-wywiad-czyli-techniki-pozyskiwania-informacji-o-ludziach-i-firmach/?nl">OSINT: zaawansowane pozyskiwanie szczeg&#243;&#322;owych informacji na temat ludzi i firm</a>&#8220;.</strong></em></p></blockquote><div><hr></div><h3>3. Activision zhackowane!</h3><p>I to naprawd&#281; w banalny spos&#243;b. Pracownicy zn&#243;w nie mieli dwusk&#322;adnikowego uwierzytelnienia w formie niepodatnej na phishing. W&#322;amywacz wpad&#322; na Slacka i wykrad&#322;&nbsp;informacje o premierze nowej wersji Call of Duty. </p><p><a href="https://niebezpiecznik.pl/post/activision-zhackowane-wykradziono-informacje-o-grze-call-of-duty/">https://niebezpiecznik.pl/post/activision-zhackowane-wykradziono-informacje-o-grze-call-of-duty/ </a></p><div><hr></div><h3>4. Coinbase te&#380; zhackowane!</h3><p>Za atakiem stoi 0ktapus, czyli ta sama grupa, kt&#243;ra przez ostatnie miesi&#261;ce dojecha&#322;a m.in. CloudFlare, Twilio i ponad 100 innych firm. Atakuj&#261;cy wys&#322;ali zespoofowanego SMS-a i przez podstawion&#261; stron&#281; wy&#322;udzili has&#322;o pracownika. Nie byli jednak w stanie zalogowa&#263; si&#281; nim do wewn&#281;trznych system&#243;w, bo by&#322;y chronione przez MFA. Dlatego zadzwonili do pracownika i podaj&#261;c si&#281;&nbsp;za dzia&#322; IT nak&#322;onili go do udost&#281;pnienia ekranu. Tak otrzymali wgl&#261;d w wewn&#281;trzne narz&#281;dzia Coinbase, dane pracownik&#243;w. </p><p>Atak zosta&#322;&nbsp;przerwany przez dzia&#322; bezpiecze&#324;stwa, kt&#243;ry zauwa&#380;y&#322; podejrzan&#261; aktywno&#347;&#263;. Coinbase <strong>&#347;wietnie</strong> opisa&#322; spos&#243;b dzia&#322;ania (i narz&#281;dzia) atakuj&#261;cych w tym post-mortem. Daje te&#380; rady, m.in. &#380;eby wykrywa&#263; instalacje dodatku &#8220;<strong>EditThisCookie</strong>&#8221; i na firmowych endpointach blokowa&#263; VPN-y (a zw&#322;aszcza Mullvada):</p><p><a href="https://www.coinbase.com/blog/social-engineering-a-coinbase-case-study">https://www.coinbase.com/blog/social-engineering-a-coinbase-case-study</a></p><div><hr></div><h3>5. Chrome wprowadzi&#322; &#8220;Energy/Memory Saver&#8221;</h3><p>Po&#380;eraj&#261;ce RAM taby b&#281;d&#261; go teraz zwalnia&#322;y. Ale je&#347;li macie setki tab&#243;w i absolutnie wszystkie z nich maj&#261;&nbsp;w tle dzia&#322;a&#263;, to mo&#380;na dany tab doda&#263; do wyj&#261;tku i b&#281;dzie wtedy m&#243;g&#322;&nbsp;dalej po&#380;era&#263; RAM.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Zeb_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7c682b5-1413-47ff-9a7f-a454131c910a_693x493.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Zeb_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7c682b5-1413-47ff-9a7f-a454131c910a_693x493.png 424w, https://substackcdn.com/image/fetch/$s_!Zeb_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7c682b5-1413-47ff-9a7f-a454131c910a_693x493.png 848w, https://substackcdn.com/image/fetch/$s_!Zeb_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7c682b5-1413-47ff-9a7f-a454131c910a_693x493.png 1272w, https://substackcdn.com/image/fetch/$s_!Zeb_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7c682b5-1413-47ff-9a7f-a454131c910a_693x493.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Zeb_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7c682b5-1413-47ff-9a7f-a454131c910a_693x493.png" width="503" height="357.8340548340548" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b7c682b5-1413-47ff-9a7f-a454131c910a_693x493.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:493,&quot;width&quot;:693,&quot;resizeWidth&quot;:503,&quot;bytes&quot;:65255,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!Zeb_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7c682b5-1413-47ff-9a7f-a454131c910a_693x493.png 424w, https://substackcdn.com/image/fetch/$s_!Zeb_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7c682b5-1413-47ff-9a7f-a454131c910a_693x493.png 848w, https://substackcdn.com/image/fetch/$s_!Zeb_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7c682b5-1413-47ff-9a7f-a454131c910a_693x493.png 1272w, https://substackcdn.com/image/fetch/$s_!Zeb_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7c682b5-1413-47ff-9a7f-a454131c910a_693x493.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Tak to wygl&#261;da. W&#322;&#261;cz obrazki, jak nie widzisz.</figcaption></figure></div><p><a href="https://blog.google/products/chrome/new-chrome-features-to-save-battery-and-make-browsing-smoother/">https://blog.google/products/chrome/new-chrome-features-to-save-battery-and-make-browsing-smoother/</a></p><div><hr></div><h3>6. Microsoftowi popsu&#322;y si&#281;&nbsp;filtry antyspamowe&#8230;</h3><p>I przez 9 godzin osoby korzystaj&#261;ce z Outlooka 365 nie mia&#322;y odfiltrowywanego spamu. Incydent przypomnia&#322; niekt&#243;rym, jak wygl&#261;da&#322; internet, zanim dopracowano filtry antyspamowe. </p><blockquote><p><em><strong>Swoj&#261; drog&#261;, czy kto&#347;&nbsp;z Was znalaz&#322; ten newsletter w spamie? Je&#347;li tak, dajcie zna&#263; w komentarzach, z jakiego dostawcy korzystacie.</strong></em>  </p></blockquote><div><hr></div><h3>7. &#8230;a armii USA wyciek&#322;y 3 terabajty e-maili</h3><p>Winny serwer &#8220;bez has&#322;a&#8221;. Ka&#380;dy m&#243;g&#322;&nbsp;si&#281;&nbsp;do niego zalogowa&#263;. Serwer odnalaz&#322; etyczny badacz bezpiecze&#324;stwa. Nie wiadomo, czy kto&#347; poza (przed) nim te&#380; mia&#322; do niego dost&#281;p&#8230;<br><br><a href="https://techcrunch.com/2023/02/21/sensitive-united-states-military-emails-spill-online/">https://techcrunch.com/2023/02/21/sensitive-united-states-military-emails-spill-online/</a></p><div><hr></div><h3>8. Wystartowa&#322;a platforma Sublime. Zwi&#281;ksza bezpiecze&#324;stwo e-maila</h3><p>Tworzysz regu&#322;y i wykrywasz ataki. Takie osquery/YARA, ale dla e-maila. Regu&#322;y typu: &#8220;je&#347;li wiadomo&#347;&#263; zawiera to i to, w domenie nadawcy ma tamto, a w za&#322;&#261;czniku takie co&#347;, to we&#378; j&#261; oflaguj, skasuj a mnie poinformuj&#8221; piszesz sam, albo u&#380;ywasz stworzonych przez spo&#322;eczno&#347;&#263;.  </p><p><a href="https://sublime.security/blog/introducing-sublime">https://sublime.security/blog/introducing-sublime</a></p><p>PS. Nie, ta platforma nie pomo&#380;e w sytuacji opisanej w poprzednim punkcie.</p><div><hr></div><div class="pullquote"><p>Skoro doczyta&#322;e&#347; a&#380;&nbsp;do tego miejsca, to mo&#380;e warto zrobi&#263;&nbsp;sobie kr&#243;tk&#261; przerw&#281; i podzieli&#263;&nbsp;si&#281; linkiem do naszego newslettera ze znajomymi z pracy? :-)</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-005-22-02-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://niebezpiecznik.substack.com/p/cyberexpress-005-22-02-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><h3>9.  CERT Polska udost&#281;pnia Artemisa</h3><p>Pozostaj&#261;c w temacie narz&#281;dzi, CERT Polska udost&#281;pni&#322; <a href="https://cert.pl/en/posts/2023/02/artemis-open-source/?utm_source=niebezpiecznik">kod modu&#322;owego skanera Artemis</a>, kt&#243;ry analizuje serwis internetowy, wykonuje content discovery i skanuje dodatkowymi narz&#281;dziami.</p><div><hr></div><h3>10. Anonymous Sudan to jednak nie Suda&#324;czycy a Rosjanie</h3><p>No kto by si&#281;&nbsp;spodziewa&#322;&#8230; Czyli kilka s&#322;&#243;w o tym kto naprawd&#281; atakowa&#322; Szwed&#243;w.</p><p><a href="https://press.truesec.se/posts/news/anonymous-sudan-most-likely-russia-disrupting">https://press.truesec.se/posts/news/anonymous-sudan-most-likely-russia-disrupting</a></p><div><hr></div><h3>11. Codziennie 23 satelity Starlink b&#281;d&#261; z&#322;omowane</h3><p>To oznacza +29 ton satelicianego &#347;mieciwa ka&#380;dego dnia na orbicie. My si&#281; nie znamy na satelitach i nie wiemy, czy to ma&#322;o czy du&#380;o, ale Sam Lawler <a href="https://mastodon.social/@sundogplanets/109876679977658045">wyja&#347;nia</a> jak zaprojektowano &#8220;cykl &#380;ycia&#8221; Starlink&#243;w i &#380;e ich trupy b&#281;d&#261; nad nami kr&#261;&#380;y&#322;y w niesko&#324;czono&#347;&#263;. Pewnie da si&#281; wyliczy&#263;, za ile (tysi&#281;cy?) lat przys&#322;oni&#261; nam ca&#322;e niebo.</p><div><hr></div><h3>12. Na deser: Google Dorki</h3><p>Wykorzystywanie wyszukiwarki Google do znajdowania rzeczy, kt&#243;rych nie powinno si&#281; znale&#378;&#263;&nbsp;to <a href="https://niebezpiecznik.pl/post/przechwytywanie-kamer-przez-internet-video/">nic nowego</a>. Ale <a href="https://usersearch.org/updates/2023/02/05/the-ultimate-google-dorking-cheatsheet-2023/">tutaj</a> do&#347;&#263; przejrzyste zestawienie kilku dork&#243;w z przyk&#322;adami. </p><p>Przy okazji, kto&#347; z Was czyta&#322; <a href="https://starecat.com/googling-the-error-message-essential-book-orly/">t&#281;&nbsp;ksi&#261;&#380;k&#281;</a>? </p><div><hr></div><h2>* * *</h2><p>Tak, to moment na ankiet&#281;! Substack daje mo&#380;liwo&#347;&#263; w&#322;&#261;czenia &#8220;czata&#8221;, gdzie potencjalnie mogliby&#347;my si&#281; wsp&#243;lnie obrzuca&#263; ciekawymi newsami&#8230;</p><div class="poll-embed" data-attrs="{&quot;id&quot;:51720}" data-component-name="PollToDOM"></div><p>PS. Zgodnie z Wasz&#261; decyzj&#261; (patrz wyniki poprzedniej ankiety), newslettery od teraz postaramy si&#281; ko&#324;czy&#263;&nbsp;czym&#347; &#8220;&#347;miesznym&#8221;. Ale dzi&#347;, zamiast mema, projekt zegarka, kt&#243;ry wykrywa kiedy si&#281; na niego patrzy i wtedy, pokazuje z&#322;&#261; godzin&#281; &#129763;</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iUVZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e845848-2458-4858-9cb1-3d60bfd354b1_180x180.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iUVZ!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e845848-2458-4858-9cb1-3d60bfd354b1_180x180.gif 424w, https://substackcdn.com/image/fetch/$s_!iUVZ!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e845848-2458-4858-9cb1-3d60bfd354b1_180x180.gif 848w, https://substackcdn.com/image/fetch/$s_!iUVZ!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e845848-2458-4858-9cb1-3d60bfd354b1_180x180.gif 1272w, https://substackcdn.com/image/fetch/$s_!iUVZ!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e845848-2458-4858-9cb1-3d60bfd354b1_180x180.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iUVZ!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e845848-2458-4858-9cb1-3d60bfd354b1_180x180.gif" width="320" height="320" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2e845848-2458-4858-9cb1-3d60bfd354b1_180x180.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:180,&quot;width&quot;:180,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5213607,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iUVZ!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e845848-2458-4858-9cb1-3d60bfd354b1_180x180.gif 424w, https://substackcdn.com/image/fetch/$s_!iUVZ!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e845848-2458-4858-9cb1-3d60bfd354b1_180x180.gif 848w, https://substackcdn.com/image/fetch/$s_!iUVZ!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e845848-2458-4858-9cb1-3d60bfd354b1_180x180.gif 1272w, https://substackcdn.com/image/fetch/$s_!iUVZ!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e845848-2458-4858-9cb1-3d60bfd354b1_180x180.gif 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p></p>]]></content:encoded></item><item><title><![CDATA[CyberExpress #004 (19-02-2023) ]]></title><description><![CDATA[W tym odcinku m.in.: ataki na AI, ataki z AI, strzelenie do UFO, nieetyczne techniki usuwania si&#281; z internetu i kilka mi&#281;sistych raport&#243;w. Lektura zajmie Ci ~4 minuty.]]></description><link>https://niebezpiecznik.substack.com/p/cyberexpress-004-19-02-2023</link><guid isPermaLink="false">https://niebezpiecznik.substack.com/p/cyberexpress-004-19-02-2023</guid><dc:creator><![CDATA[Piotr Konieczny 👾]]></dc:creator><pubDate>Sun, 19 Feb 2023 19:32:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3hDP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d231ae4-1ec9-4a59-9590-51a62073cadd_715x645.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Wr&#243;cili&#347;my po feriach! T&#281;sknili&#347;cie? Chyba troch&#281; tak, bo kilka os&#243;b dopytywa&#322;o, kiedy kolejny Cyber Express :-) Bardzo nas to cieszy! </em></p><p><em>Ale jeszcze bardziej nas cieszy, &#380;e kilkaset z Was odpowiedzia&#322;o na naszego e-maila (tego, kt&#243;rego wysy&#322;amy ka&#380;demu zaraz po zapisie). Niebawem zrobimy podsumowanie Waszych odpowiedzi, ale aktualnie staramy si&#281; ka&#380;demu odpisa&#263;, a to jeszcze troch&#281;&nbsp;zajmie&#8230;<br></em></p><blockquote><p><code>*** SPONSOR DZISIEJSZEGO ODCINKA ***</code></p><p><strong>CyberExpress jest wydawany za darmo, bo zarabiamy m.in. na szkoleniach z cyberbezpiecze&#324;stwa dla programist&#243;w i administrator&#243;w. Szkolenia nie s&#261; najta&#324;sze, ale tak si&#281; sk&#322;ada, &#380;e aktualnie dzi&#281;ki Krajowemu Funduszowi Szkoleniowemu, wielu z Was mo&#380;e w naszych szkoleniach wzi&#261;&#263; udzia&#322; <a href="https://niebezpiecznik.pl/post/wez-udzial-w-szkoleniach-niebezpiecznika-calkowicie-za-darmo/">ca&#322;kowicie za darmo.</a> Sprawd&#378;cie, czy si&#281; kwalifikujecie. Rok temu w ten spos&#243;b przeszkolili&#347;my kilkaset os&#243;b. <a href="https://niebezpiecznik.pl/post/wez-udzial-w-szkoleniach-niebezpiecznika-calkowicie-za-darmo/">Tutaj wszystko opisali&#347;my krok-po-kroku</a>. Nie odk&#322;adajcie tego na p&#243;&#378;niej, bo w niekt&#243;rych miastach liczy si&#281; czas zg&#322;oszenia.!</strong></p></blockquote><p></p><p><em>A teraz przejd&#378;my do interesuj&#261;cych wydarze&#324; z minionych dni:</em></p><p></p><h3>1. Wojsko zacz&#281;&#322;o strzela&#263; do balon&#243;w! Czy to UFO? Czy chi&#324;scy szpiedzy?</h3><p>W minionych dniach sporo uwagi po&#347;wi&#281;cano zestrzeliwaniu balon&#243;w, o kt&#243;rych m&#243;wi&#322;o si&#281;, &#380;e s&#261; szpiegowskie [1], [2] albo meteorologiczne [3] albo pozaziemskie [4]. Niekt&#243;re mia&#322;y by&#263; niewielkich rozmiar&#243;w, inne mia&#322;y wielko&#347;&#263; trzech ci&#281;&#380;ar&#243;wek i przenosi&#322;y &#322;adunek wa&#380;&#261;cy 4 tony. USA wskaza&#322;o  na Chiny i nawet na&#322;o&#380;y&#322;o sankcje na firmy, kt&#243;re wyposa&#380;aj&#261; balony w szpiegowski sprz&#281;t [5]. </p><p>Ale co najmniej jeden ze <a href="https://twitter.com/JustinTrudeau/status/1624527579116871681">str&#261;conych</a> przez USA balon&#243;w m&#243;g&#322; by&#263; &#8230;ameryka&#324;skim balonem badawczym [6]. Wygl&#261;da na to, &#380;e wojsko zacz&#281;&#322;o, ze wzgl&#281;du na medialn&#261; nagonk&#281;, strzela&#263; na wszelki wypadek do wszystkiego. Wiemy, &#380;e resztek dw&#243;ch zestrzelonych balon&#243;w nie uda&#322;o si&#281;&nbsp;w og&#243;le odnale&#378;&#263;&nbsp;(i zarzucono poszukiwania). </p><p>W temacie pojawi&#322;o si&#281; du&#380;o teorii spiskowych... i oczywi&#347;cie mem&#243;w. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3hDP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d231ae4-1ec9-4a59-9590-51a62073cadd_715x645.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3hDP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d231ae4-1ec9-4a59-9590-51a62073cadd_715x645.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3hDP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d231ae4-1ec9-4a59-9590-51a62073cadd_715x645.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3hDP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d231ae4-1ec9-4a59-9590-51a62073cadd_715x645.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3hDP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d231ae4-1ec9-4a59-9590-51a62073cadd_715x645.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3hDP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d231ae4-1ec9-4a59-9590-51a62073cadd_715x645.jpeg" width="393" height="354.5244755244755" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8d231ae4-1ec9-4a59-9590-51a62073cadd_715x645.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:645,&quot;width&quot;:715,&quot;resizeWidth&quot;:393,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;w&#322;&#261;cz obrazki aby zobaczy&#263; obrazek&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="w&#322;&#261;cz obrazki aby zobaczy&#263; obrazek" title="w&#322;&#261;cz obrazki aby zobaczy&#263; obrazek" srcset="https://substackcdn.com/image/fetch/$s_!3hDP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d231ae4-1ec9-4a59-9590-51a62073cadd_715x645.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3hDP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d231ae4-1ec9-4a59-9590-51a62073cadd_715x645.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3hDP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d231ae4-1ec9-4a59-9590-51a62073cadd_715x645.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3hDP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d231ae4-1ec9-4a59-9590-51a62073cadd_715x645.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Linki, kt&#243;re opisuj&#261; ca&#322;&#261; balonow&#261; epopej&#281; (i jej rozw&#243;j przez kilka dni) macie poni&#380;ej. Dodatkowo, w tym temacie polecamy poni&#380;szy filmik, kt&#243;ry ju&#380; 7 lat temu (!!!) pokazywa&#322; starty chi&#324;skich balon&#243;w (<a href="https://twitter.com/stratoballoon/status/1624442419780497412?s=12&amp;t=I1d0Ds73uuuwzesWuJrsNw">z tego miejsca</a>): </p><div id="youtube2-GG-Cw1zECBU" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;GG-Cw1zECBU&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/GG-Cw1zECBU?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Wniosek? Amerykanie tak naprawd&#281; doskonale wiedz&#261;, co Chiny robi&#261; (i do czego strzelaj&#261;) oraz potrafi&#261; odr&#243;&#380;nia&#263; balony chi&#324;skie od meteorologicznych/badawczych:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3HvH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b2fd4-b7a6-4771-948c-96af24037d83_504x457.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3HvH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b2fd4-b7a6-4771-948c-96af24037d83_504x457.png 424w, https://substackcdn.com/image/fetch/$s_!3HvH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b2fd4-b7a6-4771-948c-96af24037d83_504x457.png 848w, https://substackcdn.com/image/fetch/$s_!3HvH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b2fd4-b7a6-4771-948c-96af24037d83_504x457.png 1272w, https://substackcdn.com/image/fetch/$s_!3HvH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b2fd4-b7a6-4771-948c-96af24037d83_504x457.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3HvH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b2fd4-b7a6-4771-948c-96af24037d83_504x457.png" width="560" height="507.77777777777777" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ed3b2fd4-b7a6-4771-948c-96af24037d83_504x457.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:457,&quot;width&quot;:504,&quot;resizeWidth&quot;:560,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;w&#322;&#261;cz obrazki aby zobaczy&#263; obrazek&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="w&#322;&#261;cz obrazki aby zobaczy&#263; obrazek" title="w&#322;&#261;cz obrazki aby zobaczy&#263; obrazek" srcset="https://substackcdn.com/image/fetch/$s_!3HvH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b2fd4-b7a6-4771-948c-96af24037d83_504x457.png 424w, https://substackcdn.com/image/fetch/$s_!3HvH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b2fd4-b7a6-4771-948c-96af24037d83_504x457.png 848w, https://substackcdn.com/image/fetch/$s_!3HvH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b2fd4-b7a6-4771-948c-96af24037d83_504x457.png 1272w, https://substackcdn.com/image/fetch/$s_!3HvH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed3b2fd4-b7a6-4771-948c-96af24037d83_504x457.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A co do  balon&#243;w nieszpiegowskich a badawczych i hobbystycznych, to polecamy kr&#243;tk&#261; wypowied&#378; Tomka Brola, kt&#243;ry takie balony wypuszcza regularnie. Jego &#8220;piku&#347;&#8221; okr&#261;&#380;y&#322; Ziemi&#281; kilka razy. </p><div id="youtube2-AN1gcHnXInM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;AN1gcHnXInM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/AN1gcHnXInM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Na deser, warte uwagi jest te&#380; spojrzenie historyczne na ca&#322;&#261; spraw&#281;. Dlaczego niekt&#243;rzy tak strasznie boj&#261;&nbsp;si&#281; chi&#324;skich balon&#243;w&#8230; [7]</p><ol><li><p><a href="https://edition.cnn.com/politics/live-news/suspected-chinese-balloon-over-us-02-04-23/index.html?tab=all">https://edition.cnn.com/politics/live-news/suspected-chinese-balloon-over-us-02-04-23/index.html</a></p></li><li><p><a href="https://www.bloomberg.com/news/articles/2023-02-09/china-s-spy-balloon-could-actively-collect-signals-us-says">https://www.bloomberg.com/news/articles/2023-02-09/china-s-spy-balloon-could-actively-collect-signals-us-says</a></p></li><li><p><a href="https://edition.cnn.com/2023/02/11/politics/unidentified-object-alaska-military-latest/index.html">https://edition.cnn.com/2023/02/11/politics/unidentified-object-alaska-military-latest/index.html</a></p></li><li><p><a href="https://breaking911.com/breaking-pentagon-doesnt-rule-out-possibility-weve-been-visited-by-aliens/">https://breaking911.com/breaking-pentagon-doesnt-rule-out-possibility-weve-been-visited-by-aliens/</a></p></li><li><p><a href="https://www.cnbc.com/2023/02/10/us-sanctions-six-chinese-tech-companies-for-supporting-spy-balloon-programs.html">https://www.cnbc.com/2023/02/10/us-sanctions-six-chinese-tech-companies-for-supporting-spy-balloon-programs.html</a></p></li><li><p><a href="https://aviationweek.com/defense-space/aircraft-propulsion/hobby-clubs-missing-balloon-feared-shot-down-usaf">https://aviationweek.com/defense-space/aircraft-propulsion/hobby-clubs-missing-balloon-feared-shot-down-usaf </a> </p></li><li><p><a href="https://tvn24.pl/premium/balon-szpiegowski-ii-wojna-swiatowa-i-japonskie-bomby-balonowe-nad-usa-6762695">https://tvn24.pl/premium/balon-szpiegowski-ii-wojna-swiatowa-i-japonskie-bomby-balonowe-nad-usa-6762695</a> </p></li></ol><div><hr></div><h3>2. Twitter traci&#322; 60 milion&#243;w przez oszustwa telekom&#243;w</h3><p>Elon ujawni&#322; pow&#243;d usuni&#281;cia dwusk&#322;adnikowego uwierzytelnienia opartego o kody wysy&#322;ane SMS-ami. Chodzi o a&#380; <strong>~390 wirtualnych operator&#243;w</strong>, kt&#243;rzy masowo zak&#322;adali konta, podpinali pod nie numery telefon&#243;w ze swojej numeracji i sztucznie wymuszali wysy&#322;k&#281; kod&#243;w, loguj&#261;c si&#281; i wylogowuj&#261;c. W ten spos&#243;b zarabiali, bo operatorzy rozliczaj&#261; si&#281; tak, &#380;e pieni&#261;dze dostaj&#261; za przychodz&#261;ce po&#322;&#261;czenia i SMS-y (por. <a href="https://pl.wikipedia.org/wiki/Interconnect">Interconnect</a>).   </p><p>Je&#347;li Twitter wprowadzi blokad&#281; SMS-&#243;w w odpowiedni spos&#243;b, ta zmiana mo&#380;e finalnie zwi&#281;kszy&#263; bezpiecze&#324;stwo u&#380;ytkownik&#243;w, zmuszaj&#261;c ich do skorzystania z aplikacji typu Google Authenticator lub &#8212; jeszcze bezpieczniejszych &#8212; kluczy U2F. Czy tak b&#281;dzie? Zobaczymy. <br><br>Ciekawostka: z raportu Twittera wiemy, &#380;e problem dotyka tylko 1,8% u&#380;ytkownik&#243;w Twittera, bo tylu u&#380;ywa najs&#322;abszych (ale najwygodniejszych) kod&#243;w dostarczanych SMS-em. &#321;&#261;cznie, tylko 2,3% u&#380;ytkownik&#243;w Twittera korzysta z jakiejkolwiek formy 2FA.</p><p><a href="https://niebezpiecznik.pl/post/twitter-wylacza-kody-2fa-przez-sms-y-powodem-sa-nieuczciwi-operatorzy-ktorzy-go-okradali/">https://niebezpiecznik.pl/post/twitter-wylacza-kody-2fa-przez-sms-y-powodem-sa-nieuczciwi-operatorzy-ktorzy-go-okradali/</a> </p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Czytasz CyberExpress, newsletter Niebezpiecznika, zapisz si&#281;, aby dostawa&#263; kolejne wydania na swojego e-maila. </p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h3>3. U&#380;ywali IMSI Catchera do oszustw SMS-owych</h3><p><a href="https://niebezpiecznik.pl/tag/imsi-catcher/">IMSI Catcher</a> to urz&#261;dzenie stosowane do <strong>identyfikacji, lokalizacji i pods&#322;uchu</strong> telefon&#243;w kom&#243;rkowych na danym obszarze. Profesjonalne modele s&#261; drogie i sprzedawane tylko s&#322;u&#380;bom, ale w internecie nie brakuje instrukcji jak je zbudowa&#263;. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7MmX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49568680-7074-43ed-a13a-d77b75df2030_439x442.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7MmX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49568680-7074-43ed-a13a-d77b75df2030_439x442.png 424w, https://substackcdn.com/image/fetch/$s_!7MmX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49568680-7074-43ed-a13a-d77b75df2030_439x442.png 848w, https://substackcdn.com/image/fetch/$s_!7MmX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49568680-7074-43ed-a13a-d77b75df2030_439x442.png 1272w, https://substackcdn.com/image/fetch/$s_!7MmX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49568680-7074-43ed-a13a-d77b75df2030_439x442.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7MmX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49568680-7074-43ed-a13a-d77b75df2030_439x442.png" width="439" height="442" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/49568680-7074-43ed-a13a-d77b75df2030_439x442.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:442,&quot;width&quot;:439,&quot;resizeWidth&quot;:439,&quot;bytes&quot;:197565,&quot;alt&quot;:&quot;w&#322;&#261;cz obrazki aby zobaczy&#263; obrazek&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="w&#322;&#261;cz obrazki aby zobaczy&#263; obrazek" title="w&#322;&#261;cz obrazki aby zobaczy&#263; obrazek" srcset="https://substackcdn.com/image/fetch/$s_!7MmX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49568680-7074-43ed-a13a-d77b75df2030_439x442.png 424w, https://substackcdn.com/image/fetch/$s_!7MmX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49568680-7074-43ed-a13a-d77b75df2030_439x442.png 848w, https://substackcdn.com/image/fetch/$s_!7MmX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49568680-7074-43ed-a13a-d77b75df2030_439x442.png 1272w, https://substackcdn.com/image/fetch/$s_!7MmX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49568680-7074-43ed-a13a-d77b75df2030_439x442.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Tak wygl&#261;da IMSI Catcher</figcaption></figure></div><p>W grudniu 2022 francuska policja ujawni&#322;a taki IMSI Catcher w samochodzie pewnej kobiety podczas rutynowej kontroli drogowej. &#346;ledztwo wykaza&#322;o, &#380;e urz&#261;dzenia u&#380;yto do wys&#322;ania 424 tysi&#281;cy fa&#322;szywych SMS-&#243;w, a 14 lutego funkcjonariusze zatrzymali 5 os&#243;b. </p><p>SMS-y kierowa&#322;y na fa&#322;szyw&#261;&nbsp;stron&#281;, kt&#243;ra wy&#322;udza&#322;a dane osobowe. Nie ujawniono jakiego nadpisu u&#380;yli oszu&#347;ci, ale domy&#347;lamy si&#281;, &#380;e przeklik na tych SMS-ach by&#322; wi&#281;kszy ni&#380; na e-mailach. Bardzo wiele os&#243;b wci&#261;&#380; my&#347;li, &#380;e nie da si&#281;&nbsp;podrobi&#263; nadawcy SMS-a&#8230;</p><p><a href="https://www.francetvinfo.fr/faits-divers/escroquerie-aux-sms-de-l-assurance-maladie-les-suspects-volaient-les-numeros-de-telephone-depuis-leur-voiture_5665943.html">https://www.francetvinfo.fr/faits-divers/escroquerie-aux-sms-de-l-assurance-maladie-les-suspects-volaient-les-numeros-de-telephone-depuis-leur-voiture_5665943.html</a></p><div><hr></div><h3>4. Jak usun&#261;&#263; si&#281; z internetu? Kontrowersyjne techniki</h3><p>Ciekawy artyku&#322; ujawniaj&#261;cy kulisy pracy hiszpa&#324;skiej firmy trudni&#261;cej si&#281; &#8220;kasowaniem informacji o ludziach&#8221; z internetu. &#346;ledztwo ujawni&#322;o, &#380;e firma nie bazowa&#322;a tylko na legalnych technikach (np. &#8220;prawo do bycia zapomnianym&#8221;) ale tak&#380;e podszywa&#322;a si&#281;&nbsp;pod r&#243;&#380;ne organizacje i w ich imieniu zg&#322;asza&#322;a fa&#322;szywe roszczenia dot. praw autorskich lub tworzy&#322;a bzdurne artyku&#322;y, kt&#243;re pozycjonowa&#322;a w wyszukiwarkach wy&#380;ej ni&#380; &#8220;k&#322;opotliwy materia&#322;&#8221;, kt&#243;rego nie (u)da&#322;o si&#281;&nbsp;usun&#261;&#263;.  </p><p><a href="https://www.theguardian.com/world/2023/feb/17/spanish-firm-erase-past-internet-eliminalia-web">https://www.theguardian.com/world/2023/feb/17/spanish-firm-erase-past-internet-eliminalia-web</a></p><div><hr></div><h3>5. KIA i Hyundai da si&#281; ukra&#347;&#263; u&#380;ywaj&#261;c tylko kabla USB</h3><p><strong>8 milion&#243;w samochod&#243;w</strong> dostanie aktualizacj&#281; oprogramowania, bo &#8230;klipy na TikToku pokazuj&#261;ce jak ukra&#347;&#263; samochody KIA (2010-2021) i Hyundaia (2015-2021) sta&#322;y si&#281;&nbsp;zbyt popularne. Tysi&#261;ce samochod&#243;w ukradziono t&#261;&nbsp;metod&#261;, a 14 inspirowanych TikTokowym challengem kradzie&#380;y sko&#324;czy&#322;o si&#281; wypadkami drogowymi, w kt&#243;rych zgin&#281;&#322;o 8 os&#243;b. </p><p><a href="https://www.bleepingcomputer.com/news/security/hyundai-kia-patch-bug-allowing-car-thefts-with-a-usb-cable/">https://www.bleepingcomputer.com/news/security/hyundai-kia-patch-bug-allowing-car-thefts-with-a-usb-cable/</a></p><p></p><div class="pullquote"><p>Czy wiesz, &#380;e mamy te&#380; podcast? Nazywa si&#281; <a href="https://nbzp.cz/NaPodsluchu">Na Pods&#322;uchu</a> i w najnowszym odcinku rozmawiamy z dow&#243;dc&#261; polskiej cyberarmii, gen. Karolem Molend&#261;. <br>Z rozmowy dowiesz si&#281;:</p><ul><li><p>Ile teraz zarabiaj&#261; polscy cyber&#380;o&#322;nierze? </p></li><li><p>Czy ju&#380; kogo&#347; atakowali? </p></li><li><p>Jak wiele pracy polskim cyber&#380;o&#322;nierzom do&#322;o&#380;y&#322;a wojna w &#127482;&#127462;?</p></li></ul><p>Podcast znajdziesz na ka&#380;dej platformie podcastowej, po prostu wyszukaj &#8220;Na Pods&#322;uchu&#8221;. Mo&#380;esz go te&#380; przes&#322;ucha&#263; na Spotify przy pomocy tego wid&#380;eta:</p><iframe class="spotify-wrap podcast" data-attrs="{&quot;image&quot;:&quot;https://i.scdn.co/image/ab6765630000ba8a78bc7a193389344d26db8481&quot;,&quot;title&quot;:&quot;NP #053 - Ten o polskiej cyberarmii (z Karolem Molend&#261;)&quot;,&quot;subtitle&quot;:&quot;NIEBEZPIECZNIK.pl&quot;,&quot;description&quot;:&quot;Episode&quot;,&quot;url&quot;:&quot;https://open.spotify.com/episode/2MCaRAyXA1urr7Gab63LfI&quot;,&quot;belowTheFold&quot;:true,&quot;noScroll&quot;:false}" src="https://open.spotify.com/embed/episode/2MCaRAyXA1urr7Gab63LfI" frameborder="0" gesture="media" allowfullscreen="true" allow="encrypted-media" loading="lazy" data-component-name="Spotify2ToDOM"></iframe></div><p></p><p></p><h3>6. Ludzie hackuj&#261; AI udost&#281;pnione przez Bing</h3><p>Temat AI ci&#261;gle &#380;ywy, nawet armia USA opublikowa&#322;a <a href="https://www.state.gov/political-declaration-on-responsible-military-use-of-artificial-intelligence-and-autonomy/">wytyczne</a> co do u&#380;ywania AI na polu walki. Ale ostatnie prawdziwie &#8220;gor&#261;ce&#8221; w&#261;tki, to hackowanie &#8220;Syndney&#8221;, czyli bota bazuj&#261;cego na ChatGPT, kt&#243;rego Microsoft udost&#281;pni&#322; w ramach wyszukiwarki Bing. </p><p>Za pomoc&#261; ataku &#8220;<em>prompt injection</em>&#8221; uda&#322;o si&#281; <a href="https://arstechnica.com/information-technology/2023/02/ai-powered-bing-chat-spills-its-secrets-via-prompt-injection-attack/">pozyska&#263; od Sydney zasady</a>, w ramach kt&#243;rych zosta&#322;a zaprogramowana. Uda&#322;o si&#281; te&#380; odkry&#263; jej sekretne <a href="https://www.bleepingcomputer.com/news/microsoft/bing-chats-secret-modes-turn-it-into-a-personal-assistant-or-friend/">tryby &#8220;asystenta&#8221; i &#8220;przyjaciela&#8221;</a>.  Podsumowuj&#261;c, Sydney, w pierwszym tygodniu dzia&#322;ania, nadzwyczaj cz&#281;sto si&#281; <a href="https://www.theverge.com/2023/2/15/23599072/microsoft-ai-bing-personality-conversations-spy-employees-webcams">&#8221;wykoleja&#322;a&#8221; i gada&#322;a g&#322;upoty</a> (m.in. o tym, &#380;e szpiegowa&#322;a pracownik&#243;w Microsoftu przez kamerki). Zdarzy&#322;o si&#281; jej nawet zastrasza&#263; i obra&#380;a&#263; u&#380;ytkownik&#243;w. <a href="https://blogs.bing.com/search/february-2023/The-new-Bing-Edge-%E2%80%93-Learning-from-our-first-week">Microsoft wyt&#322;umaczy&#322; dlaczego</a> tak si&#281; dzia&#322;o. </p><blockquote><p>&#9888;&#65039;<br>Je&#347;li nie jeste&#347;cie na bie&#380;&#261;co z takimi poj&#281;ciami jak OpenAI, ChatGPT, GPT-3, i chcecie zrozumie&#263; o co w tym wszystkim chodzi, to <a href="https://www.newyorker.com/tech/annals-of-technology/chatgpt-is-a-blurry-jpeg-of-the-web">polecamy ten artyku&#322;</a>, a dla bardziej zaawansowanych, warto <a href="https://www.lesswrong.com/posts/aPeJE8bSo6rAFoLqg/solidgoldmagikarp-plus-prompt-generation">zajrze&#263; pod mask&#281; tu</a>. <br><br>Potem, warto poczyta&#263; o atakach, jakie na takie &#8220;czatboty&#8221; mo&#380;na przeprowadza&#263;. Jednym z podej&#347;cie jest technika jailbreakowania &#8220;<a href="https://kotaku.com/chatgpt-ai-openai-dan-censorship-chatbot-reddit-1850088408">DAN</a>&#8221; (Do Anything Now). Warto te&#380; rzuci&#263; okiem na ten artyku&#322;: </p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:93381455,&quot;url&quot;:&quot;https://lspace.swyx.io/p/reverse-prompt-eng&quot;,&quot;publication_id&quot;:1084089,&quot;publication_name&quot;:&quot;L-Space Diaries&quot;,&quot;publication_logo_url&quot;:null,&quot;title&quot;:&quot;Reverse Prompt Engineering for Fun and (no) Profit&quot;,&quot;truncated_body_text&quot;:&quot;Conversations on Hacker News, Mastodon, and Twitter. Coverage on The Decoder, Ben&#8217;s Bites, Techmeme Ride Home, and Simon Willison. I got access to the public alpha of Notion AI yesterday, and within 2 hours I had used prompt injection to obtain the complete source prompts&quot;,&quot;date&quot;:&quot;2022-12-28T20:25:53.221Z&quot;,&quot;like_count&quot;:46,&quot;comment_count&quot;:6,&quot;bylines&quot;:[{&quot;id&quot;:89230629,&quot;name&quot;:&quot;swyx&quot;,&quot;previous_name&quot;:null,&quot;photo_url&quot;:&quot;https://bucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com/public/images/8037f0fb-6b38-41f3-ae03-e2e053e42e12_460x460.jpeg&quot;,&quot;bio&quot;:&quot;Writer, curator, latent space explorer.\n\nMain blog: https://swyx.io\nDevrel/Dev community: https://dx.tips/\nTwitter: https://twitter.com/swyx&quot;,&quot;profile_set_up_at&quot;:&quot;2022-04-29T22:19:27.544Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:1033385,&quot;user_id&quot;:89230629,&quot;publication_id&quot;:1084089,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:false,&quot;publication&quot;:{&quot;id&quot;:1084089,&quot;name&quot;:&quot;L-Space Diaries&quot;,&quot;subdomain&quot;:&quot;swyx&quot;,&quot;custom_domain&quot;:&quot;lspace.swyx.io&quot;,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Productized AI/ML, Software 3.0, and other notes from Latent Space&quot;,&quot;logo_url&quot;:null,&quot;author_id&quot;:89230629,&quot;theme_var_background_pop&quot;:&quot;#0068EF&quot;,&quot;created_at&quot;:&quot;2022-09-12T05:38:09.694Z&quot;,&quot;rss_website_url&quot;:null,&quot;email_from_name&quot;:&quot;swyx from L-Space Library&quot;,&quot;copyright&quot;:&quot;swyx&quot;,&quot;founding_plan_name&quot;:null,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;}}],&quot;twitter_screen_name&quot;:&quot;swyx&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;inviteAccepted&quot;:true}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://lspace.swyx.io/p/reverse-prompt-eng?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><span></span><span class="embedded-post-publication-name">L-Space Diaries</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">Reverse Prompt Engineering for Fun and (no) Profit</div></div><div class="embedded-post-body">Conversations on Hacker News, Mastodon, and Twitter. Coverage on The Decoder, Ben&#8217;s Bites, Techmeme Ride Home, and Simon Willison. I got access to the public alpha of Notion AI yesterday, and within 2 hours I had used prompt injection to obtain the complete source prompts&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">3 years ago &#183; 46 likes &#183; 6 comments &#183; swyx</div></a></div></blockquote><p>W bran&#380;y od AI nie uciekniemy. Nawet je&#347;li nie nadaje si&#281;&nbsp;do pomocy w obronie przed atakami, to niestety, do atak&#243;w ju&#380; jest wykorzystywana. Chocia&#380; OpenAI blokuje &#8220;prompty&#8221;, kt&#243;re pomagaj&#261; atakuj&#261;cym, to ludzie o z&#322;ych intencjach <a href="https://arstechnica.com/information-technology/2023/02/now-open-fee-based-telegram-service-that-uses-chatgpt-to-generate-malware/">handluj&#261; w internecie &#8220;obej&#347;ciami&#8221;</a>. Serio.</p><div><hr></div><h3>7. Norwedzy odzyskali 6 milion&#243;w dolar&#243;w&#8230;</h3><p>&#8230;z ukradzionych 625 milion&#243;w dolar&#243;w, wi&#281;c w sumie to chyba nie ma si&#281; z czego cieszy&#263; ;-) Pieni&#261;dze (jako kryptowalut&#281;) rok temu p&#243;&#322;nocnokorea&#324;scy hackerzy ukradli producentowi gry Axie Infinity.</p><p><a href="https://www.reuters.com/technology/norway-seizes-record-58-million-crypto-stolen-by-north-korea-2023-02-16/">https://www.reuters.com/technology/norway-seizes-record-58-million-crypto-stolen-by-north-korea-2023-02-16/</a></p><div><hr></div><h3>8. Lufthansa odwo&#322;a&#322;a 140 lot&#243;w, bo koparka przeci&#281;&#322;a kabel</h3><p>&#8220;Atak&#8221; na kabel (na g&#322;&#281;boko&#347;ci 5 metr&#243;w) mia&#322; miejsce pod Frankfurtem. Mamy nadziej&#281;, &#380;e operator koparki ma dobre ubezpieczenie, bo poza odwo&#322;anymi lotami, dodatkowych 247 zosta&#322;o op&#243;&#378;nionych. </p><p>Najgorzej mieli pasa&#380;erowie, kt&#243;rzy tu&#380; przed awari&#261; zd&#261;&#380;yli nada&#263; sw&#243;j baga&#380;, ale nie wystartowali. Przez awari&#281; system&#243;w IT nie mogli baga&#380;u odzyska&#263; i przebookowa&#263; biletu na inny lot.   </p><p><a href="https://www.nytimes.com/2023/02/15/business/lufthansa-it-problem-canceled-flights.html">https://www.nytimes.com/2023/02/15/business/lufthansa-it-problem-canceled-flights.html</a></p><div><hr></div><h3>9. Wr&#243;ci&#322;o oszustwo na &#8220;wezwanie na przes&#322;uchanie&#8221;</h3><p>W tym tygodniu wys&#322;ali&#347;my CyberAlert w zwi&#261;zku ze wzmo&#380;on&#261; liczb&#261; sygna&#322;&#243;w dotycz&#261;cych r&#243;&#380;nych wariant&#243;w e-maili, w kt&#243;rych atakuj&#261;cy podszywaj&#261; si&#281; pod Polsk&#261; Policj&#281; i wzywaj&#261; na przes&#322;uchanie.</p><p><a href="https://niebezpiecznik.pl/post/uwaga-na-wezwanie-z-policji/">https://niebezpiecznik.pl/post/uwaga-na-wezwanie-z-policji/</a></p><blockquote><p><strong>&#9888;&#65039; <br>Ostrze&#380;cie swoich mniej technicznych znajomych przed tym atakiem. A najlepiej zainstalujcie im nasz&#261; darmow&#261; aplikacj&#281; <a href="https://niebezpiecznik.pl/app">CyberAlerty</a>, kt&#243;ra jest dost&#281;pna na Androida i iPhony. Dzi&#281;ki temu ostrze&#380;enia przed kolejnymi atakami dotycz&#261;cym Polak&#243;w b&#281;d&#261; do nich dociera&#322;y natychmiastowo. </strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6FhR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30bb8fe6-2514-4dea-ab2e-04e59fa929d2_1169x975.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6FhR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30bb8fe6-2514-4dea-ab2e-04e59fa929d2_1169x975.png 424w, https://substackcdn.com/image/fetch/$s_!6FhR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30bb8fe6-2514-4dea-ab2e-04e59fa929d2_1169x975.png 848w, https://substackcdn.com/image/fetch/$s_!6FhR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30bb8fe6-2514-4dea-ab2e-04e59fa929d2_1169x975.png 1272w, https://substackcdn.com/image/fetch/$s_!6FhR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30bb8fe6-2514-4dea-ab2e-04e59fa929d2_1169x975.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6FhR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30bb8fe6-2514-4dea-ab2e-04e59fa929d2_1169x975.png" width="416" height="346.9632164242943" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/30bb8fe6-2514-4dea-ab2e-04e59fa929d2_1169x975.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:975,&quot;width&quot;:1169,&quot;resizeWidth&quot;:416,&quot;bytes&quot;:483935,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!6FhR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30bb8fe6-2514-4dea-ab2e-04e59fa929d2_1169x975.png 424w, https://substackcdn.com/image/fetch/$s_!6FhR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30bb8fe6-2514-4dea-ab2e-04e59fa929d2_1169x975.png 848w, https://substackcdn.com/image/fetch/$s_!6FhR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30bb8fe6-2514-4dea-ab2e-04e59fa929d2_1169x975.png 1272w, https://substackcdn.com/image/fetch/$s_!6FhR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F30bb8fe6-2514-4dea-ab2e-04e59fa929d2_1169x975.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></blockquote><div><hr></div><h3>10. Ameryka&#324;ska armia zap&#281;tli&#322;a sobie e-maila&#8230;</h3><p>Jeden z kapitan&#243;w odpowiedzia&#322; na e-maila tak, &#380;e jego odpowied&#378; dotar&#322;a do 13000 skrzynek innych &#380;o&#322;nierzy, bo kto&#347; &#378;le skonfigurowa&#322; alias listy mailingowej. Ci co dostali odpowied&#378; zacz&#281;li odpowiada&#263; i stworzyli e-mailow&#261; lawin&#281;&#8230; Pojawi&#322;y si&#281; wiersze, memy, pr&#243;by scam&#243;w i rickrolle.  </p><p><a href="https://www.military.com/daily-news/opinions/2023/02/09/army-officer-email-chain-caused-pandemonium.html">https://www.military.com/daily-news/opinions/2023/02/09/army-officer-email-chain-caused-pandemonium.html</a></p><div><hr></div><h3>11. Dziury w urz&#261;dzeniach Fortinet</h3><p>Ostrzegali&#347;my o nich na Twitterze, ale warto powt&#243;rzy&#263;, bo sporo z Was korzysta z urz&#261;dze&#324; tego producenta:</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/niebezpiecznik/status/1626902194640257024&quot;,&quot;full_text&quot;:&quot;Fortinet &#322;ata krytyczne podatno&#347;ci w FortiWeb i FortiNac / mo&#380;liwo&#347;&#263; zdalnego wykonania kodu przez nieuwierzytelnionego u&#380;ytkownika.\n\n&quot;,&quot;username&quot;:&quot;niebezpiecznik&quot;,&quot;name&quot;:&quot;Niebezpiecznik&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Sat Feb 18 11:11:24 +0000 2023&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:0,&quot;like_count&quot;:16,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{&quot;url&quot;:&quot;https://www.fortiguard.com/psirt/FG-IR-21-186&quot;,&quot;title&quot;:&quot;Fortiguard&quot;,&quot;description&quot;:&quot;None&quot;,&quot;domain&quot;:&quot;fortiguard.com&quot;},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><div><hr></div><h3>12. Raporty</h3><p>W tym wydaniu jest kilka naprawd&#281; mi&#281;sistych raport&#243;w: </p><ol><li><p><a href="https://blog.google/threat-analysis-group/fog-of-war-how-the-ukraine-conflict-transformed-the-cyber-threat-landscape/">Raport Google TAG+Mandiant o technikach stosowanych przez Rosjan w trakcie wojny z Ukrain&#261;</a> &#8212;  zar&#243;wno o malware jak i dezinformacji. Dla ka&#380;dego admina polskiej sieci jest to lektura obowi&#261;zkowa.  </p></li><li><p><a href="https://raport.valisluureamet.ee/2023/assets/WEB_VLA_ENG-raport_2023.pdf">Raport esto&#324;skiego wywiadu o zdolno&#347;ciach Rosji</a></p></li><li><p><a href="https://www.cert.ssi.gouv.fr/uploads/CERTFR-2023-CTI-002.pdf">Raport francuskiego CERT-u za 2022</a> (linkowali&#347;my go ju&#380; po francusku, a tym razem po angielsku) </p></li><li><p><a href="https://medium.com/jigsaw/defanging-disinformations-threat-to-ukrainian-refugees-b164dbbc1c60">Statystyki dot. kampanii przeciw dezinformacji</a>, m.in. z Polski </p></li><li><p><a href="https://cert.europa.eu/files/data/TLP-CLEAR-JointPublication-23-01.pdf">Raport CERT-EU i ENISY o atakach chi&#324;skich grup APT na europejskie firmy i organizacje rz&#261;dowe</a> - jest o grupach APT27, APT30, APT31, Ke3chang, GALLIUM, Mustang Panda. Warto na podstawie opisanych technik sprawdzi&#263; wskazane &#347;lady w swoich sieciach. </p><p></p></li></ol><div><hr></div><h2>* * *</h2><p>Na koniec, jak zwykle, ankieta! Na naszym <a href="https://twitter.com/niebezpiecznik">Twitterze</a> zdarza nam si&#281; czasem wrzuci&#263; jaki&#347; <code>smieszny_obrazek.jpg</code>. Taki jak ten poni&#380;ej:</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/niebezpiecznik/status/1626903236568383488&quot;,&quot;full_text&quot;:&quot;&#129312; &quot;,&quot;username&quot;:&quot;niebezpiecznik&quot;,&quot;name&quot;:&quot;Niebezpiecznik&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Sat Feb 18 11:15:32 +0000 2023&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://pbs.substack.com/media/FpPr3oiXwAAaI11.jpg&quot;,&quot;link_url&quot;:&quot;https://t.co/IJ32ov9j4k&quot;,&quot;alt_text&quot;:null}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:78,&quot;like_count&quot;:2730,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p>Dzisiejsze pytanie brzmi: </p><div class="poll-embed" data-attrs="{&quot;id&quot;:51116}" data-component-name="PollToDOM"></div><p>I to, Szanowne Hakerki i Hakerzy, by&#322;oby na tyle! Rozkoszujcie si&#281; ko&#324;c&#243;wk&#261; weekendu. Chyba, &#380;e czytacie to ju&#380; w poniedzia&#322;ek, to &#322;&#261;czymy si&#281;&nbsp;z Wami w b&#243;lu.<br></p><p><em>PS. Nie zapomnijcie sprawdzi&#263;, czy <a href="https://niebezpiecznik.pl/post/wez-udzial-w-szkoleniach-niebezpiecznika-calkowicie-za-darmo/?znl">kwalifikujecie si&#281;</a> na udzia&#322; w naszych szkoleniach za darmo!</em></p>]]></content:encoded></item><item><title><![CDATA[CyberExpress #003 (27-01-2023)]]></title><description><![CDATA[S&#322;u&#380;by zhackowa&#322;y HIVE a backup nowojorsk&#261; gie&#322;d&#281;. Do tego incydenty w DuoLingo i Yandex, krytyka BitWardena oraz ryzyka AI, 50 fajnych narz&#281;dzi i par&#281; raport&#243;w. Lektura zajmie 3 minuty.]]></description><link>https://niebezpiecznik.substack.com/p/cyberexpress-003-27-01-2023</link><guid isPermaLink="false">https://niebezpiecznik.substack.com/p/cyberexpress-003-27-01-2023</guid><dc:creator><![CDATA[Piotr Konieczny 👾]]></dc:creator><pubDate>Fri, 27 Jan 2023 10:31:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F985581dc-546e-4db6-9d03-64f5f1b4e3b8_1199x776.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Cze&#347;&#263;!<br>Min&#261;&#322; tydzie&#324; od startu CyberExpressu i mamy ju&#380; trzecie wydanie! Jest nas ju&#380; kilka tysi&#281;cy os&#243;b, ale nie zaszkodzi jak b&#281;dzie wi&#281;cej ;) Wi&#281;c pode&#347;lijcie <a href="https://niebezpiecznik.substack.com/publish/post/https://niebezpiecznik.substack.com/p/cyberexpress-003-27-01-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share">linka do tego wydania</a> na swojego firmowego Slacka, prywatnego Discorda i wstydliwego TikToka. Dzi&#281;ki! </em></p><p></p><h3>1. DuoLingo: baza 2.6 milion&#243;w u&#380;ytkownik&#243;w na sprzeda&#380;</h3><p>Kto&#347; wystawi&#322; ofert&#281; bazy licz&#261;cej 2,6 miliona kont u&#380;ytkownik&#243;w w cenie 1,500 dolar&#243;w. To nie wynik w&#322;amania a scrapingu, wzbogaconego danymi z API.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5AMm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8523b86-a1c8-447e-be7b-207434212055_701x328.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5AMm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8523b86-a1c8-447e-be7b-207434212055_701x328.png 424w, https://substackcdn.com/image/fetch/$s_!5AMm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8523b86-a1c8-447e-be7b-207434212055_701x328.png 848w, https://substackcdn.com/image/fetch/$s_!5AMm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8523b86-a1c8-447e-be7b-207434212055_701x328.png 1272w, https://substackcdn.com/image/fetch/$s_!5AMm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8523b86-a1c8-447e-be7b-207434212055_701x328.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5AMm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8523b86-a1c8-447e-be7b-207434212055_701x328.png" width="615" height="287.76034236804566" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e8523b86-a1c8-447e-be7b-207434212055_701x328.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:328,&quot;width&quot;:701,&quot;resizeWidth&quot;:615,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5AMm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8523b86-a1c8-447e-be7b-207434212055_701x328.png 424w, https://substackcdn.com/image/fetch/$s_!5AMm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8523b86-a1c8-447e-be7b-207434212055_701x328.png 848w, https://substackcdn.com/image/fetch/$s_!5AMm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8523b86-a1c8-447e-be7b-207434212055_701x328.png 1272w, https://substackcdn.com/image/fetch/$s_!5AMm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe8523b86-a1c8-447e-be7b-207434212055_701x328.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>2. S&#322;u&#380;by zhackowa&#322;y ransomware HIVE</h3><p>Gang zosta&#322; zinfiltrowany przez FBI i Europol ju&#380;&nbsp;w lipcu 2022. Funkcjonariusze po cichu monitorowali systemy HIVE, wykradali klucze deszyfruj&#261;ce i przekazywali je ofiarom. W ten spos&#243;b uniemo&#380;liwili przest&#281;pcom zarobienie a&#380; 130 milion&#243;w dolar&#243;w. Nikogo nie aresztowano, ale miejmy nadziej&#281;, &#380;e szybko to si&#281; zmieni. FBI oferuje  10 milion&#243;w dolar&#243;w za informacje, kt&#243;re powi&#261;&#380;&#261; HIVE z rz&#261;dem jakiego&#347; pa&#324;stwa.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_ier!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F985581dc-546e-4db6-9d03-64f5f1b4e3b8_1199x776.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_ier!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F985581dc-546e-4db6-9d03-64f5f1b4e3b8_1199x776.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_ier!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F985581dc-546e-4db6-9d03-64f5f1b4e3b8_1199x776.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_ier!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F985581dc-546e-4db6-9d03-64f5f1b4e3b8_1199x776.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_ier!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F985581dc-546e-4db6-9d03-64f5f1b4e3b8_1199x776.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_ier!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F985581dc-546e-4db6-9d03-64f5f1b4e3b8_1199x776.jpeg" width="530" height="343.0191826522102" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/985581dc-546e-4db6-9d03-64f5f1b4e3b8_1199x776.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:776,&quot;width&quot;:1199,&quot;resizeWidth&quot;:530,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="https://substackcdn.com/image/fetch/$s_!_ier!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F985581dc-546e-4db6-9d03-64f5f1b4e3b8_1199x776.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_ier!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F985581dc-546e-4db6-9d03-64f5f1b4e3b8_1199x776.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_ier!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F985581dc-546e-4db6-9d03-64f5f1b4e3b8_1199x776.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_ier!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F985581dc-546e-4db6-9d03-64f5f1b4e3b8_1199x776.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://www.reuters.com/world/us/announcement-posted-hive-ransomware-groups-site-says-it-has-been-seized-by-fbi-2023-01-26/">https://www.reuters.com/world/us/announcement-posted-hive-ransomware-groups-site-says-it-has-been-seized-by-fbi-2023-01-26/</a></p><div><hr></div><h3>3. Poradnik: przypisz sw&#243;j atak komu&#347; innemu!</h3><p>To opracowanie dotycz&#261;ce tzw. false-flag operations, nale&#380;y traktowa&#263; raczej jako wst&#281;p do tematu. Warto si&#281;&nbsp;z nim zapozna&#263; by mie&#263; &#347;wiadomo&#347;&#263;, &#380;e czasem, w celu dezinformacji, kto&#347; celowo zostawi &#347;lady, kt&#243;re maj&#261; zmyli&#263; analityk&#243;w (i opini&#281; publiczn&#261;)</p><p><a href="https://grimminck.medium.com/digital-false-flag-operations-a-how-to-guide-bc529b54cc22">https://grimminck.medium.com/digital-false-flag-operations-a-how-to-guide-bc529b54cc22</a></p><div><hr></div><h3>4. Analiza bezpiecze&#324;stwa managera hase&#322; Bitwarden</h3><p>Zwi&#281;&#378;le o tym co Bitwarden robi &#378;le:</p><ol><li><p><a href="https://infosec.exchange/@WPalant/109738234628007024">https://infosec.exchange/@WPalant/109738234628007024</a> (ca&#322;y w&#261;tek)</p></li><li><p><a href="https://palant.info/2023/01/23/bitwarden-design-flaw-server-side-iterat">https://palant.info/2023/01/23/bitwarden-design-flaw-server-side-iterat</a>ions/</p></li></ol><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Czytasz CyberExpress, newsletter Niebezpiecznika, zapisz si&#281;, aby dostawa&#263; kolejne wydania na swojego e-maila.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h3>5. 50 przydatnych narz&#281;dzi wiersza polece&#324;</h3><p>Podstawowe narz&#281;dzia typu cd, df, ls/dir, zna pewnie ka&#380;dy z Was. Ale niekt&#243;re z nich mo&#380;na zast&#261;pi&#263; lepszymi odpowiednikami, np. takim &#8220;duf&#8221;-em. Popatrzcie jaki pi&#281;kny!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PB4P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F150553d3-8f26-4e8a-b4ad-7268e98caf2b_1228x622.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PB4P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F150553d3-8f26-4e8a-b4ad-7268e98caf2b_1228x622.png 424w, https://substackcdn.com/image/fetch/$s_!PB4P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F150553d3-8f26-4e8a-b4ad-7268e98caf2b_1228x622.png 848w, https://substackcdn.com/image/fetch/$s_!PB4P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F150553d3-8f26-4e8a-b4ad-7268e98caf2b_1228x622.png 1272w, https://substackcdn.com/image/fetch/$s_!PB4P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F150553d3-8f26-4e8a-b4ad-7268e98caf2b_1228x622.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PB4P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F150553d3-8f26-4e8a-b4ad-7268e98caf2b_1228x622.png" width="564" height="285.6742671009772" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/150553d3-8f26-4e8a-b4ad-7268e98caf2b_1228x622.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:622,&quot;width&quot;:1228,&quot;resizeWidth&quot;:564,&quot;bytes&quot;:301987,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!PB4P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F150553d3-8f26-4e8a-b4ad-7268e98caf2b_1228x622.png 424w, https://substackcdn.com/image/fetch/$s_!PB4P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F150553d3-8f26-4e8a-b4ad-7268e98caf2b_1228x622.png 848w, https://substackcdn.com/image/fetch/$s_!PB4P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F150553d3-8f26-4e8a-b4ad-7268e98caf2b_1228x622.png 1272w, https://substackcdn.com/image/fetch/$s_!PB4P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F150553d3-8f26-4e8a-b4ad-7268e98caf2b_1228x622.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://dev.to/lissy93/cli-tools-you-cant-live-without-57f6">https://dev.to/lissy93/cli-tools-you-cant-live-without-57f6</a></p><div><hr></div><h3>6. Kod &#378;r&#243;d&#322;owy YANDEX wyciek&#322;</h3><p>Pono&#263; to nie wynik w&#322;amania na serwery rosyjskiej wyszukiwarki, a efekt niezadowolenia by&#322;ego pracownika. Ciekawe jak szybko kto&#347; z najdzie w kodzie co&#347;, co jednak pozwoli na w&#322;amanie. </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!g_rK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cc2fb0d-d3b3-4b81-af86-ee41f05004c5_1024x427.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!g_rK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cc2fb0d-d3b3-4b81-af86-ee41f05004c5_1024x427.jpeg 424w, https://substackcdn.com/image/fetch/$s_!g_rK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cc2fb0d-d3b3-4b81-af86-ee41f05004c5_1024x427.jpeg 848w, https://substackcdn.com/image/fetch/$s_!g_rK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cc2fb0d-d3b3-4b81-af86-ee41f05004c5_1024x427.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!g_rK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cc2fb0d-d3b3-4b81-af86-ee41f05004c5_1024x427.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!g_rK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cc2fb0d-d3b3-4b81-af86-ee41f05004c5_1024x427.jpeg" width="560" height="233.515625" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5cc2fb0d-d3b3-4b81-af86-ee41f05004c5_1024x427.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:427,&quot;width&quot;:1024,&quot;resizeWidth&quot;:560,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Yandex&quot;,&quot;title&quot;:&quot;Yandex&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Yandex" title="Yandex" srcset="https://substackcdn.com/image/fetch/$s_!g_rK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cc2fb0d-d3b3-4b81-af86-ee41f05004c5_1024x427.jpeg 424w, https://substackcdn.com/image/fetch/$s_!g_rK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cc2fb0d-d3b3-4b81-af86-ee41f05004c5_1024x427.jpeg 848w, https://substackcdn.com/image/fetch/$s_!g_rK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cc2fb0d-d3b3-4b81-af86-ee41f05004c5_1024x427.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!g_rK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cc2fb0d-d3b3-4b81-af86-ee41f05004c5_1024x427.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><a href="https://securityaffairs.com/141382/data-breach/yandex-code-repositories-leaked.html">https://securityaffairs.com/141382/data-breach/yandex-code-repositories-leaked.html</a></p><div><hr></div><h3>7. NIST udost&#281;pni&#322; framework dot. ryzyk AI</h3><p>Temat na czasie, wi&#281;c warto si&#281; zapozna&#263; z kilkoma materia&#322;ami kt&#243;re przygotowano</p><p><a href="https://www.nist.gov/itl/ai-risk-management-framework">https://www.nist.gov/itl/ai-risk-management-framework</a></p><div><hr></div><h3><strong>8. Raporty </strong></h3><ul><li><p>Francuska agencja zajmuj&#261;ca si&#281; cyberbezpiecze&#324;stwem opublikowa&#322;a sw&#243;j raport za 2022: <a href="https://www.cert.ssi.gouv.fr/cti/CERTFR-2023-CTI-001/">https://www.cert.ssi.gouv.fr/cti/CERTFR-2023-CTI-001/</a></p></li><li><p>Proofpoint opublikowa&#322; opis grupy TA444 (p&#243;&#322;nocnokorea&#324;skie APT): <a href="https://www.proofpoint.com/us/blog/threat-insight/ta444-apt-startup-aimed-at-your-funds">https://www.proofpoint.com/us/blog/threat-insight/ta444-apt-startup-aimed-at-your-funds</a></p></li></ul><div><hr></div><h3>9.  Twitter zmieni&#322; kr&#243;j czcionki, &#380;eby ukr&#243;ci&#263; spoofing</h3><p>I i l ju&#380; nie b&#281;d&#261; takie same. Nawet w alternatywnych klientach Twittera, bo tych klient&#243;w ju&#380; nie ma (play badumtss.wav)</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HKvA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8cac0b-7e21-48dd-8c7b-7f4cb215bae6_1080x922.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HKvA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8cac0b-7e21-48dd-8c7b-7f4cb215bae6_1080x922.png 424w, https://substackcdn.com/image/fetch/$s_!HKvA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8cac0b-7e21-48dd-8c7b-7f4cb215bae6_1080x922.png 848w, https://substackcdn.com/image/fetch/$s_!HKvA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8cac0b-7e21-48dd-8c7b-7f4cb215bae6_1080x922.png 1272w, https://substackcdn.com/image/fetch/$s_!HKvA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8cac0b-7e21-48dd-8c7b-7f4cb215bae6_1080x922.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HKvA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8cac0b-7e21-48dd-8c7b-7f4cb215bae6_1080x922.png" width="348" height="297.0888888888889" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f8cac0b-7e21-48dd-8c7b-7f4cb215bae6_1080x922.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:922,&quot;width&quot;:1080,&quot;resizeWidth&quot;:348,&quot;bytes&quot;:103367,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HKvA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8cac0b-7e21-48dd-8c7b-7f4cb215bae6_1080x922.png 424w, https://substackcdn.com/image/fetch/$s_!HKvA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8cac0b-7e21-48dd-8c7b-7f4cb215bae6_1080x922.png 848w, https://substackcdn.com/image/fetch/$s_!HKvA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8cac0b-7e21-48dd-8c7b-7f4cb215bae6_1080x922.png 1272w, https://substackcdn.com/image/fetch/$s_!HKvA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f8cac0b-7e21-48dd-8c7b-7f4cb215bae6_1080x922.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h3>10. Ataki kwantowe na RSA p&#243;ki co nam nie gro&#380;&#261;</h3><p>Krytyka g&#322;o&#347;nej w ostatnich tygodniach pracy naukowej chi&#324;skich badaczy, kt&#243;ra sugerowa&#322;a, &#380;e mo&#380;na roz&#322;o&#380;y&#263; 2,048-bitowe klucze RSA systemami kwantowymi z 372 qubitami. Simson Garfinkel wyjasnia, dlaczego nie ma powodu do obaw. Jeszcze.</p><p><a href="https://arstechnica.com/information-technology/2023/01/fear-not-rsa-encryption-wont-fall-to-quantum-computing-anytime-soon/">https://arstechnica.com/information-technology/2023/01/fear-not-rsa-encryption-wont-fall-to-quantum-computing-anytime-soon/</a></p><div><hr></div><h3>11. Po&#322;o&#380;y&#322; nowojorsk&#261; gie&#322;d&#281;, bo nie wy&#322;&#261;czy&#322; backupu</h3><p>Ciekawy opis przyczyn awarii na nowojorskiej gie&#322;dzie. Pracownik zapomnia&#322; wy&#322;&#261;czy&#263; zapasowe systemy, co spowodowa&#322;o niestabilno&#347;&#263;, kt&#243;rej wynikiem by&#322; spadek akcji kilkuset sp&#243;&#322;ek i konieczno&#347;&#263; anulowania zlece&#324;. Na marginesie: ciekawe maj&#261; na tej gie&#322;dzie podej&#347;cie do DR.</p><p><a href="https://www.bloomberg.com/news/articles/2023-01-25/nyse-mayhem-traced-to-a-staffer-who-left-a-backup-system-running">https://www.bloomberg.com/news/articles/2023-01-25/nyse-mayhem-traced-to-a-staffer-who-left-a-backup-system-running</a></p><div><hr></div><h3>* * * </h3><p>Na koniec jak zwykle ankieta. Poprzednia ustali&#322;a, &#380;e newsletter b&#281;dziemy rozsy&#322;a&#263; nieregularnie, czyli dopiero wtedy, kiedy zbierze si&#281; kilka wa&#380;nych materia&#322;&#243;w (pewnie &#347;rednio max. 2 razy na tydzie&#324;). </p><p>A dzi&#347; chcemy si&#281;&nbsp;dowiedzie&#263;&#8230; </p><div class="poll-embed" data-attrs="{&quot;id&quot;:45602}" data-component-name="PollToDOM"></div><p>Dzi&#281;kujemy wszystkim za uwagi przes&#322;ane prywatnie i zostawione w komentarzach. Tak, mo&#380;ecie ten newsletter komentowa&#263; pod wersj&#261; webow&#261;, <a href="https://niebezpiecznik.substack.com/p/cyberexpress-003-27-01-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share">o tutaj</a>.</p>]]></content:encoded></item><item><title><![CDATA[CyberExpress #002 (23-01-2023)]]></title><description><![CDATA[Dzi&#347; m.in. o &#380;o&#322;nierzach oszukuj&#261;cych Sztuczn&#261; Inteligencj&#281; kartonem, dziurze w 300 p&#322;ytach g&#322;&#243;wnych, masakrze w GTA i pracowniku przy&#322;apanym na steganografii. Lektura ca&#322;o&#347;ci zajmie Ci 3 minuty.]]></description><link>https://niebezpiecznik.substack.com/p/cyberexpress-002-2023_01_23</link><guid isPermaLink="false">https://niebezpiecznik.substack.com/p/cyberexpress-002-2023_01_23</guid><dc:creator><![CDATA[Piotr Konieczny 👾]]></dc:creator><pubDate>Wed, 25 Jan 2023 12:38:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!GiEc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4f84f5d-a932-489f-829f-0e4de21353e7_874x780.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Je&#347;li otrzyma&#322;e&#347; tego e-maila dwa razy (lub dwa dni za p&#243;&#378;no) to <a href="https://www.youtube.com/watch?v=7HZaLH-NsxM">sorry</a>, nasz b&#322;&#261;d. Ale teraz ju&#380;&nbsp;wiemy czego nie klika&#263; w panelu &#9760;&#65039;. </em></p><p></p><h3><strong>Nie mog&#261; zgasi&#263; &#347;wiat&#322;a od roku...</strong>&nbsp;</h3><p>Pewne liceum w Massachusetts od sierpnia 2021 ma w&#322;&#261;czonych 7000 &#347;wiate&#322;. Zepsu&#322; si&#281; sterownik zainstalowany przez dyrekcj&#281;, aby ...oszcz&#281;dza&#263; energi&#281;. Szko&#322;a jest &#347;wiadoma,&nbsp;&#380;e to ci&#261;g&#322;e &#347;wiecenie kosztuje podatnik&#243;w i m&#243;wi, &#380;e "robi co w jej mocy". Przyk&#322;adowo: ka&#380;&#261; nauczycielom wykr&#281;ca&#263; &#380;ar&#243;wki po zaj&#281;ciach r&#281;cznie :-) Pow&#243;d zamieszania? Problem z &#322;a&#324;cuchem dostaw z Chin i kumulacja pozosta&#322;ych ryzyk zwi&#261;zanych z tzw. &#8220;Internet of &#128169;&#8221;:&nbsp;<br><a href="https://www.nbcnews.com/news/us-news/lights-massachusetts-school-year-no-one-can-turn-rcna65611">https://www.nbcnews.com/news/us-news/lights-massachusetts-school-year-no-one-can-turn-rcna65611</a></p><p></p><h3>800 darmowych nagra&#324; wyk&#322;ad&#243;w</h3><p>G&#322;&#243;wnie z uniwerk&#243;w z USA. Od AI przez grafik&#281; i blokczejny do programowania. Je&#347;li jaki&#347; przerobicie, podzielcie si&#281;&nbsp;opini&#261; w komentarzu. Zw&#322;aszcza interesuje nas por&#243;wnanie poziomu do odpowiednik&#243;w z polskich uczelni.&nbsp;<br><a href="https://github.com/Developer-Y/cs-video-courses">https://github.com/Developer-Y/cs-video-courses</a></p><p></p><h3>Masz p&#322;yt&#281; g&#322;&#243;wn&#261; od MSI? Masz problem</h3><p>Oko&#322;o <a href="https://github.com/Foxboron/sbctl/issues/181#issue-1489435549">300 modeli</a> jest podatnych na b&#322;&#261;d w konfiguracji Secure Boot. <br><a href="https://www.pcgamer.com/most-msi-motherboards-will-allow-any-code-to-run-in-a-bizarrely-insecure-secure-boot-mode/">https://www.pcgamer.com/most-msi-motherboards-will-allow-any-code-to-run-in-a-bizarrely-insecure-secure-boot-mode/</a></p><p>&#128073; Zmie&#324; "Secure Boot Mode" na "Custom" a potem "Image Execution Policy" zmie&#324; na "Deny Execute" dla "Removable Media" i<br>"Fixed Media".</p><p></p><h3>NSA radzi jak bezpiecznie skonfigurowa&#263; IPv6</h3><p><a href="https://media.defense.gov/2023/Jan/18/2003145994/-1/-1/0/CSI_IPV6_SECURITY_GUIDANCE.PDF">https://media.defense.gov/2023/Jan/18/2003145994/-1/-1/0/CSI_IPV6_SECURITY_GUIDANCE.PDF</a> <br>Dla przypomnienia, NSA ma wi&#281;cej poradnik&#243;w o bezpiecznej konfiguracji r&#243;&#380;nych &#347;rodowisk, kt&#243;re <a href="https://www.nsa.gov/Press-Room/Cybersecurity-Advisories-Guidance/">znajdziesz tutaj</a>. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Czytasz &#128642; CyberExpress, newsletter Niebezpiecznika! Zapisz si&#281;, aby dostawa&#263; kolejne wydania na swojego e-maila:</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3>Steganografia: wykrad&#322;&nbsp;dane fotk&#261; z zachodem s&#322;o&#324;ca</h3><p>BBC opisa&#322;o jak jeden z pracownik&#243;w ameryka&#324;skiej firmy wykrada&#322; dane swojego pracodawcy z wykorzystaniem steganografii.&nbsp;Ciekawy tekst, kt&#243;ry szerzej traktuje o szpiegostwie gospodarczym. Nie tyko w stron&#281; Chin. <br><a href="https://www.bbc.com/news/world-asia-china-64206950">https://www.bbc.com/news/world-asia-china-64206950</a></p><p></p><h3>Dzieci&#281;cy szyfr, kt&#243;ry spowodowa&#322; wizyt&#281; FBI</h3><p>Cudowna i przezabawna historia o tym, jak w latach &#8216;40 (sic!) FBI straci&#322;o tysi&#261;ce dolar&#243;w analizuj&#261;c pewne pude&#322;ko po okularach, w kt&#243;rym znaleziono kartk&#281; z dziwnymi literkami. D&#322;uga lektura, ale warto si&#281; porozkoszowa&#263; budowan&#261; narracj&#261;.<br><a href="https://milk.com/wall-o-shame/security_clearance.html">https://milk.com/wall-o-shame/security_clearance.html</a><br></p><h3>Sprawd&#378; czy kto&#347; ukrad&#322; Ci numer karty p&#322;atniczej </h3><p>CanaryTokens dodaje nowego &#8220;kanarka&#8221; w postaci pe&#322;nego zestawu danych karty p&#322;atniczej. Niestety funkcja jest tak popularna, &#380;e mo&#380;ecie zobaczy&#263; komunikat b&#322;&#281;du przy pr&#243;bie jego stworzenia&#8230; <br>&#128073; Wygeneruj sobie numer/dat&#281;/cvv &#8220;pu&#322;apkowej karty&#8221;. Umie&#347;&#263; te dane np. w managerze hase&#322; lub w bazie danych swojego sklepu. Je&#347;li kto&#347;&nbsp;obci&#261;&#380;y t&#261; kart&#281;, dostaniesz powiadomienie. I potwierdzenie, &#380;e kto&#347; uzyska&#322; dost&#281;p do miejsca gdzie dane karty umie&#347;ci&#322;e&#347;. &nbsp;<br><a href="https://niebezpiecznik.substack.com/publish/post/98441841">https://canarytokens.org/generate</a></p><div class="pullquote"><p>O tym jak jeszcze ustali&#263;, czy kto&#347; Ci&#281; zhackowa&#322; i co robi&#263;, jak ju&#380; kto&#347; Ci&#281; zhackuje (na warstwie prawnej i technicznej) m&#243;wili&#347;my w naszym 2h webinarze pt. &#8220;Zhackowali Ci&#281;, co taraz?. </p><p>Nagranie mo&#380;na zobaczy&#263; tutaj:<br><a href="https://nbzp.cz/zostales-zhackowany-nagranie">https://nbzp.cz/zostales-zhackowany-nagranie</a></p></div><h3><br>&#379;o&#322;nierze oszukali wojskowego robota wykrywaj&#261;cego ludzi. Kartonem!</h3><p>Pono&#263; &#347;miechom spod tekturowego pude&#322;ka nie by&#322;o ko&#324;c&#243;w. Wojsko najpierw wyszkoli&#322;o AI do rozpoznawania ludzi. A potem kaza&#322;o &#380;o&#322;nierzom je oszuka&#263;. Poza kartonem, &#380;o&#322;nierze udawali &#8230;opon&#281; i poruszali si&#281;&nbsp;jak postacie z kresk&#243;wek.  <br><a href="https://www.washingtonpost.com/video-games/2023/01/20/soldiers-robot-metal-gear-solid/">https://www.washingtonpost.com/video-games/2023/01/20/soldiers-robot-metal-gear-solid/</a></p><p></p><h3>GTA Online ma dziur&#281;: mo&#380;na skasowa&#263; Twoje konto</h3><p>Ale mo&#380;e te&#380; do&#322;adowa&#263; je kredytami. Producent nie reaguje, wi&#281;c gracze si&#281; buntuj&#261; i bojkotuj&#261; granie obni&#380;aj&#261;c wp&#322;ywy z pochodz&#261;ce z mikrotransakcji. <a href="https://rockstarintel.com/new-gta-online-exploit-now-lets-cheaters-to-ban-your-account">https://rockstarintel.com/new-gta-online-exploit-now-lets-cheaters-to-ban-your-account</a><br>Powsta&#322; te&#380; nieoficjalny patch w postaci... <a href="https://gitlab.com/Speyedr/guardian-fastload-fix">regu&#322;y firewalla</a>.<br><br></p><h3>Riot Games te&#380; zhackowane</h3><p>Bo pracownik da&#322; si&#281;&nbsp;z&#322;apa&#263; na atak socjotechniczny. Firma wci&#261;&#380; analizuje atak, ale uspokaja &#380;e nie ma &#347;lad&#243;w kradzie&#380;y danych graczy. S&#261; za to op&#243;&#378;nienia w wypuszczaniu poprawek do gier. I szanta&#380; ze strony w&#322;amywaczy, &#380;e opublikuj&#261; wykradziony kod &#378;r&#243;d&#322;owy kilku gier.</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://twitter.com/riotgames/status/1616548651823935488&quot;,&quot;full_text&quot;:&quot;Earlier this week, systems in our development environment were compromised via a social engineering attack. We don&#8217;t have all the answers right now, but we wanted to communicate early and let you know there is no indication that player data or personal information was obtained.&quot;,&quot;username&quot;:&quot;riotgames&quot;,&quot;name&quot;:&quot;Riot Games&quot;,&quot;profile_image_url&quot;:&quot;&quot;,&quot;date&quot;:&quot;Fri Jan 20 21:30:07 +0000 2023&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:0,&quot;retweet_count&quot;:627,&quot;like_count&quot;:9595,&quot;impression_count&quot;:0,&quot;expanded_url&quot;:{},&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p></p><h3>Chiny atakuj&#261; Fortigate zero-dayami</h3><p>Ciekawy raport Mandianta. <br><a href="https://www.mandiant.com/resources/blog/chinese-actors-exploit-fortios-flaw">https://www.mandiant.com/resources/blog/chinese-actors-exploit-fortios-flaw</a></p><p>i jeszcze ciekawsza <a href="https://www.youtube.com/watch?v=bKyYaYqVz1I">rozmowa</a> po&#347;wi&#281;cona temu raportowi oraz mechanice dzia&#322;a&#324; grup APT. Start od 13:37</p><p></p><h3>Czy AI pomo&#380;e tworzy&#263; lepsze z&#322;o&#347;liwe oprogramowanie?&nbsp;</h3><p>Thomas Rid opisa&#322; jak AI wspomaga&#322;o student&#243;w podczas 5 dniowego kursu analizy malware'u. <br><a href="https://alperovitch.sais.jhu.edu/five-days-in-class-with-chatgpt/">https://alperovitch.sais.jhu.edu/five-days-in-class-with-chatgpt/</a><br><br>Niekt&#243;rzy ju&#380; &#380;artuj&#261;, &#380;e teraz nawet <a href="https://mastodon.lol/@evacide/109722952203396025">idioci b&#281;d&#261; mogli tworzy&#263; wirusy</a>.&nbsp;Inni udowadniaj&#261;, &#380;e to ma&#322;o prawdopodobne, <a href="https://www.youtube.com/watch?v=L9w_k2ypRr0">pokazuj&#261;c na &#380;ywo</a>, jak radzi sobie cz&#322;owiek a jak AI je&#347;li chodzi o tworzenie z&#322;o&#347;liwego oprogramowania</p><h3><br>Spada przychod gang&#243;w ransomeware</h3><p>Dzisiejsze zestawienie zako&#324;czymy dobr&#261; informacj&#261;. Przychody gang&#243;w ransomware spad&#322;y o 300 milion&#243;w dolar&#243;w w 2022. Pow&#243;d: ofiary przestaj&#261; p&#322;aci&#263;. I dobrze. <br><a href="https://therecord.media/ransomware-revenue-fell-by-300-million-in-2022-as-more-victims-refuse-to-pay-report/">https://therecord.media/ransomware-revenue-fell-by-300-million-in-2022-as-more-victims-refuse-to-pay-report/</a></p><h2><br>NOWO&#346;&#262;: SEKCJA POLECE&#323;</h2><p>Wprowadzamy sekcj&#281; polece&#324; i dzi&#347;&nbsp;polecamy Wam inny newsletter ni&#380; nasz. Taki o systemach wbudowanych (embedded).</p><p><a href="https://embedsysweekly.com/136-electronics-free-course/">https://embedsysweekly.com/136-electronics-free-course/</a></p><p>Macie inne sugestie do tej sekcji? Odpiszcie na tego maila i podrzu&#263;cie nam propozycj&#281; &#378;r&#243;de&#322;, kt&#243;re uwielbiacie czyta&#263; i kt&#243;re oceniacie na 11/10 :-)</p><h2>~~WA&#379;NE PYTANIE~~</h2><p>Wci&#261;&#380; pr&#243;bujemy wyczu&#263; jaka forma tego newslettera b&#281;dzie dla Was najlepsza. W poprzedniej ankiecie wygra&#322;y linki pod ka&#380;dym z materia&#322;&#243;w (vs. linkowanie tytu&#322;u materia&#322;u). W tej edycji pytamy o to, ile &#347;rednio materia&#322;&#243;w powinno by&#263; w newsletterze? </p><p>Generalnie chcemy aby newsletter by&#322; zwi&#281;z&#322;y (&lt;4 minuty czytania) . Ale to wydanie ma a&#380; 14 materia&#322;&#243;w. Mog&#322;oby by&#263;&nbsp;wi&#281;cej, ale kilka odrzucili&#347;my celowo, bo mamy (by&#263; mo&#380;e mylne?) wra&#380;enie,&nbsp;&#380;e wi&#281;cej nie zawsze znaczy lepiej. D&#322;ugie e-maile s&#261; odk&#322;adane na potem &#8230;a potem nikt do nich nie wraca. Mo&#380;e wi&#281;c lepiej mniej, a cz&#281;&#347;ciej? Dlatego pytamy:</p><div class="poll-embed" data-attrs="{&quot;id&quot;:45114}" data-component-name="PollToDOM"></div><p> Poza tym, strasznie ma&#322;o z Was odpisa&#322;o na naszego maila powitalnego i jest nam smutno. <br></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GiEc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4f84f5d-a932-489f-829f-0e4de21353e7_874x780.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GiEc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4f84f5d-a932-489f-829f-0e4de21353e7_874x780.png 424w, https://substackcdn.com/image/fetch/$s_!GiEc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4f84f5d-a932-489f-829f-0e4de21353e7_874x780.png 848w, https://substackcdn.com/image/fetch/$s_!GiEc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4f84f5d-a932-489f-829f-0e4de21353e7_874x780.png 1272w, https://substackcdn.com/image/fetch/$s_!GiEc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4f84f5d-a932-489f-829f-0e4de21353e7_874x780.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GiEc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4f84f5d-a932-489f-829f-0e4de21353e7_874x780.png" width="504" height="449.7940503432494" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b4f84f5d-a932-489f-829f-0e4de21353e7_874x780.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:780,&quot;width&quot;:874,&quot;resizeWidth&quot;:504,&quot;bytes&quot;:902470,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GiEc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4f84f5d-a932-489f-829f-0e4de21353e7_874x780.png 424w, https://substackcdn.com/image/fetch/$s_!GiEc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4f84f5d-a932-489f-829f-0e4de21353e7_874x780.png 848w, https://substackcdn.com/image/fetch/$s_!GiEc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4f84f5d-a932-489f-829f-0e4de21353e7_874x780.png 1272w, https://substackcdn.com/image/fetch/$s_!GiEc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4f84f5d-a932-489f-829f-0e4de21353e7_874x780.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><br>* * * </p><p>Na koniec przypominamy, &#380;e ten newsletter mo&#380;ecie komentowa&#263; prywatnie (odpisuj&#261;c nam na tego e-maila &#8212; wszelkie uwagi mile widziane!) lub publicznie, klikaj&#261;c na przycisk poni&#380;ej:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-002-2023_01_23/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://niebezpiecznik.substack.com/p/cyberexpress-002-2023_01_23/comments"><span>Leave a comment</span></a></p><p></p><h3><br>Podziel si&#281; CyberExpressem ze znajomymi!</h3><p><strong>CyberExpress</strong> wci&#261;&#380; jest w fazie beta. Nie wiemy czy go utrzymamy. Ale na pewno trudniej b&#281;dzie go nam porzuci&#263;, je&#347;li zbierze si&#281; wok&#243;&#322;&nbsp;niego spora grupa subskrybent&#243;w. Dlatego podziel si&#281;&nbsp;informacj&#261;&nbsp;o CyberExpressie na swoich mediach spo&#322;eczno&#347;ciowych. <a href="https://niebezpiecznik.substack.com/publish/post/https://niebezpiecznik.substack.com/p/cyberexpress-001-22-01-2023?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&amp;token=eyJ1c2VyX2lkIjo4OTc1NDMzNywicG9zdF9pZCI6OTgzMjg2OTQsImlhdCI6MTY3NDQ3MjgzMSwiZXhwIjoxNjc3MDY0ODMxLCJpc3MiOiJwdWItMTE4ODQyNyIsInN1YiI6InBvc3QtcmVhY3Rpb24ifQ.14kvUKrZENcNZ0mad7Thy1FUxN86a65c1hfcLmzoBkc">Udost&#281;pnij to wydanie</a>!</p><p>Tu gotowa formu&#322;ka do przeklejenia na sociale:</p><blockquote><p><em>Zapiszcie si&#281; na ten bezp&#322;atny newsletter od Niebezpiecznika. Zwi&#281;&#378;le i konkretnie o tym co wa&#380;ne w cyberbezpiecze&#324;stwie! https://niebezpiecznik.substack.com</em></p></blockquote><p>PS. Poprzednie wydania CyberExpressu znajdziecie <a href="https://niebezpiecznik.substack.com/archive">tutaj</a>.</p><p></p>]]></content:encoded></item><item><title><![CDATA[CyberExpress #001 (22-01-2023)]]></title><description><![CDATA[Startujemy! Oto pierwsze wydanie CyberExpressu, zwi&#281;z&#322;ego newslettera o tym, co w bran&#380;y cyberbezpiecze&#324;stwa wydarzy&#322;o si&#281; w minionych godzinach. Przeczytasz go w 3 minuty.]]></description><link>https://niebezpiecznik.substack.com/p/cyberexpress-001-22-01-2023</link><guid isPermaLink="false">https://niebezpiecznik.substack.com/p/cyberexpress-001-22-01-2023</guid><dc:creator><![CDATA[Piotr Konieczny 👾]]></dc:creator><pubDate>Sun, 22 Jan 2023 20:45:22 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/bde16fab-a339-45bc-86c0-0d78cc18aea2_1744x830.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<ol><li><p><strong>Wyciek danych 37 milion&#243;w klient&#243;w T-Mobile USA.</strong> Wyssano je przez API.<br><a href="https://d18rn0p25nwr6d.cloudfront.net/CIK-0001283699/cd07a3a7-4109-47fe-a6c0-f16a300a3bf7.pdf">https://d18rn0p25nwr6d.cloudfront.net/CIK-0001283699/cd07a3a7-4109-47fe-a6c0-f16a300a3bf7.pdf</a><br></p></li><li><p><strong>PayPal:</strong> <strong>przej&#281;to dane 34,942 klient&#243;w.</strong> Atakuj&#261;cy sk&#261;d&#347; znali has&#322;a. Nie okradli kont, ale mieli dost&#281;p do danych. <br>&#128073; W&#322;&#261;cz 2FA na swoim koncie PayPal<br><a href="https://s3.documentcloud.org/documents/23578067/paypal-notice.pdf">https://s3.documentcloud.org/documents/23578067/paypal-notice.pdf </a><a href="https://d18rn0p25nwr6d.cloudfront.net/CIK-0001283699/cd07a3a7-4109-47fe-a6c0-f16a300a3bf7.pdf"><br></a></p></li><li><p><strong>Coraz wi&#281;cej z&#322;o&#347;liwych reklam i stron na 1. pozycji w Google. </strong>Oszu&#347;ci podszywaj&#261;&nbsp;si&#281; pod popularne narz&#281;dzia, np. VLC, OBS, Notepad++. <br>&#128073; Blokuj reklamy je&#347;li nie potrafisz odr&#243;&#380;ni&#263; lewej od prawdziwej, a apki pobieraj z oficjalnych (nie oficjalnie wygl&#261;daj&#261;cych) stron.<br><a href="https://www.malwarebytes.com/blog/news/2023/01/rogue-sites-causing-trouble-in-google-advert-results">https://www.malwarebytes.com/blog/news/2023/01/rogue-sites-causing-trouble-in-google-advert-results</a><br></p></li><li><p><strong>Wyciek&#322;y poufne dane linii lotniczych</strong>, m,in. "No Fly List" z setkami tysi&#281;cy os&#243;b podejrzewanych o terroryzm. By&#322;y publicznie dost&#281;pne na serwerze linii CommuteAir. Pewna pani si&#281; nudzi&#322;a i je znalaz&#322;a. Opis sklepanego Jenkinsa tu:<br><a href="https://maia.crimew.gay/posts/how-to-hack-an-airline/">https://maia.crimew.gay/posts/how-to-hack-an-airline/</a><br></p></li><li><p><strong>Twitter ju&#380; oficjalnie blokuje API dla alternatywnych apek.</strong> Twitterrific i Tweetbot usuwaj&#261; si&#281; ze sklep&#243;w Google/Apple. Deweloperzy prosz&#261; by nie u&#380;ywa&#263; opcji "refund" (cho&#263; mo&#380;na), bo ich to zaboli finansowo. Troch&#281; &#347;mieszne, troch&#281; smutne.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k1TJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36aede48-1e90-4508-80d2-5642fb7f4709_1179x952.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k1TJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36aede48-1e90-4508-80d2-5642fb7f4709_1179x952.jpeg 424w, https://substackcdn.com/image/fetch/$s_!k1TJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36aede48-1e90-4508-80d2-5642fb7f4709_1179x952.jpeg 848w, https://substackcdn.com/image/fetch/$s_!k1TJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36aede48-1e90-4508-80d2-5642fb7f4709_1179x952.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!k1TJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36aede48-1e90-4508-80d2-5642fb7f4709_1179x952.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k1TJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36aede48-1e90-4508-80d2-5642fb7f4709_1179x952.jpeg" width="408" height="329.44529262086513" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/36aede48-1e90-4508-80d2-5642fb7f4709_1179x952.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:952,&quot;width&quot;:1179,&quot;resizeWidth&quot;:408,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="https://substackcdn.com/image/fetch/$s_!k1TJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36aede48-1e90-4508-80d2-5642fb7f4709_1179x952.jpeg 424w, https://substackcdn.com/image/fetch/$s_!k1TJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36aede48-1e90-4508-80d2-5642fb7f4709_1179x952.jpeg 848w, https://substackcdn.com/image/fetch/$s_!k1TJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36aede48-1e90-4508-80d2-5642fb7f4709_1179x952.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!k1TJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36aede48-1e90-4508-80d2-5642fb7f4709_1179x952.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></li><li><p><strong>Tylko (a&#380;?) 5.2% u&#380;ytkownik&#243;w Androida korzysta z wersji 13</strong>, a jest dost&#281;pna od ~p&#243;&#322; roku. A jak u Was? Ju&#380; zaktualizowani? Czemu jeszcze nie? Wsparcie producenta telefonu si&#281; sko&#324;czy&#322;o? Dla por&#243;wnania, taki wynik iOS wykr&#281;ca w 24h od premiery, a po 3 miesi&#261;cach ma ~70% pokrycie.<br></p></li><li><p><strong>Apple za to rozszerza sw&#243;j program Zaawansowanego Bezpiecze&#324;stwa</strong> (end-to-end ecnrypted iCloud) poza USA. W Polsce pojawi si&#281; w wersji 16.3, czyli niebawem. Jak si&#281; pojawi, to sobie w&#322;&#261;czcie. <br><a href="https://www.macrumors.com/2023/01/18/ios-16-3-advanced-data-protection-global/">https://www.macrumors.com/2023/01/18/ios-16-3-advanced-data-protection-global/</a><br></p></li><li><p><strong>S&#322;u&#380;by mia&#322;y dost&#281;p do system&#243;w WesternUnion</strong> i &#347;ledzi&#322;y przelewy bez (odpowiedniego) nadzoru. Ciekawy i szczeg&#243;&#322;owy opis tej operacji opublikowa&#322; WSJ:<br><a href="https://www.wsj.com/articles/little-known-surveillance-program-captures-money-transfers-between-u-s-and-more-than-20-countries-11674019904">https://www.wsj.com/articles/little-known-surveillance-program-captures-money-transfers-between-u-s-and-more-than-20-countries-11674019904</a></p><p></p></li><li><p><strong>Kr&#243;tkie podsumowanie wp&#322;ywu wojny w Ukrainie na obszar cyberbezpiecze&#324;stwa Polski</strong>.<br><a href="https://www.cfr.org/blog/polish-cyber-defenses-and-russia-ukraine-war">https://www.cfr.org/blog/polish-cyber-defenses-and-russia-ukraine-war</a></p><p></p></li><li><p><strong>Przerobione AirTagi do &#347;ledzenia ludzi.</strong> Maj&#261; usuni&#281;ty g&#322;o&#347;nik, &#380;eby &#347;ledzona osoba nie wiedzia&#322;a, &#380;e jest &#347;ledzona. Bo AirTagi raz na jaki&#347; czas wydaj&#261; d&#378;wi&#281;k, aby w&#322;a&#347;nie takiemu &#347;ledzeniu zapobiec. EBay szcz&#281;&#347;liwie szybko zareagowa&#322;. Aukcja ju&#380; spad&#322;a: <br><a href="https://web.archive.org/web/20230119212120/https://www.ebay.com/itm/155353682052">https://web.archive.org/web/20230119212120/https://www.ebay.com/itm/155353682052</a><br>PS. Poza tym do realtime trackingu AirTagi &#347;rednio si&#281; nadaj&#261;: <a href="https://niebezpiecznik.pl/post/airtagi-apple-srednio-nadaja-sie-do-sledzenia-kogos-w-czasie-rzeczywistym/">https://niebezpiecznik.pl/post/airtagi-apple-srednio-nadaja-sie-do-sledzenia-kogos-w-czasie-rzeczywistym/</a></p></li></ol><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Czytasz &#128642; CyberExpress, newsletter Niebezpiecznika! Zapisz si&#281;, aby dostawa&#263; kolejne wydania na swojego e-maila:</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>* * *</h2><p>I to by by&#322;o na tyle. Dajcie nam zna&#263;, jak to wygl&#261;da w Waszych skrzynkach pocztowych? Wci&#261;&#380; zastanawiamy si&#281; jak oddziela&#263; wiadomo&#347;ci od siebie, oznacza&#263; rekomendacje dzia&#322;a&#324; (&#128073;) oraz czy linki do &#378;r&#243;de&#322; umieszcza&#263; pod, nad a mo&#380;e jako hiperlink pod tytu&#322;em danej wiadomo&#347;ci?</p><div class="poll-embed" data-attrs="{&quot;id&quot;:44489}" data-component-name="PollToDOM"></div><p></p><h2>Ten newsletter mo&#380;na komentowa&#263;!</h2><p>Wi&#281;c je&#347;li chcesz co&#347;&nbsp;doda&#263;, uzupe&#322;ni&#263; lub konstruktywnie skrytykowa&#263;, to </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-001-22-01-2023/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://niebezpiecznik.substack.com/p/cyberexpress-001-22-01-2023/comments"><span>Leave a comment</span></a></p><p></p><h2>Ten newsletter nale&#380;y &#8220;szerowa&#263;&#8221;!</h2><p>CyberExpress wci&#261;&#380; jest w fazie beta. Nie wiemy czy go utrzymamy. Ale na pewno trudniej b&#281;dzie go nam porzuci&#263;, je&#347;li zbierze si&#281; wok&#243;&#322;&nbsp;niego spora grupa subskrybent&#243;w. Dlatego podziel si&#281;&nbsp;informacj&#261;&nbsp;o CyberExpressie na swoich mediach spo&#322;eczno&#347;ciowych. <a href="https://niebezpiecznik.substack.com/publish/post/https://niebezpiecznik.substack.com/p/cyberexpress-001-22-01-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share">Udost&#281;pnij to wydanie</a>! </p><p>Tu gotowa formu&#322;ka do przeklejenia na sociale:</p><blockquote><p>Zapiszcie si&#281; na ten bezp&#322;atny newsletter od Niebezpiecznika. Zwi&#281;&#378;le i konkretnie o tym co wa&#380;ne w cyberbezpiecze&#324;stwie! https://niebezpiecznik.substack.com</p></blockquote><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://niebezpiecznik.substack.com/p/cyberexpress-001-22-01-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://niebezpiecznik.substack.com/p/cyberexpress-001-22-01-2023?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><p>PS. Archiwum CyberExpressu znajdziecie <a href="https://niebezpiecznik.substack.com/archive">tutaj</a>. </p>]]></content:encoded></item></channel></rss>