Human Security BLIK SMS spoofing: how one link hijacks your banking
An intensive campaign impersonates BLIK using SMS spoofing and fake login panels. We show how criminals take over online banking and how to break the chain.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Human Security An intensive campaign impersonates BLIK using SMS spoofing and fake login panels. We show how criminals take over online banking and how to break the chain.
Penetration Testing and AppSec WordPress powers most of the web and is the top target for attacks. Ten practical steps to secure your site — no coding knowledge required.
Cloud, Infrastructure and DevSecOps Kubernetes gives huge flexibility and an equally large attack surface. We cover the most common mistakes — RBAC, secrets, networking — and hardening priorities.
Human Security A call from the bank's number, a calm 'consultant' and a supposed break-in on your account. We break down the fake-bank-employee scam and how to stop it.
Governance and Compliance DORA has applied since January 2025 and covers far more than banks. The five pillars, mandatory resilience testing and ICT supplier duties.
Penetration Testing and AppSec APIs are now the most common target for application attacks. We cover the key OWASP API Top 10 flaws — led by BOLA — and how to avoid them.
Human Security Phishing still accounts for most successful breaches. We explain why employee education alone isn't enough and what to add to your defences.
Human Security Fake shops, spoofed payments and intercepted cards. A practical guide to spotting a fraudulent store and paying safely online.
Supply Chain Security Your security ends at your weakest supplier. How to assess contractor risk, what to put in contracts and how to monitor suppliers efficiently.
Threats and Incidents Your passwords and data are almost certainly in some breach. How to check it safely, what a leak really means and what steps to take.
Governance and Compliance Employees use several times more applications than IT has approved. Where shadow IT comes from, what it risks and how to control it without bans.
Human Security A fake parcel-fee text leads to card or banking phishing. Learn how to inspect the domain, authorisation prompt and incident response.
Penetration Testing and AppSec A guide to the OWASP Top 10 for teams that want to understand real risks — from broken access control, through injection, to SSRF.
Vulnerabilities and CVEs The scanner is the easy part. How to build the full process: inventory, risk-based prioritisation, remediation SLAs and metrics that matter.
Supply Chain Security Pickle, SafeTensors, ONNX, and AI checkpoints explained: prevent code execution and build a controlled, verifiable model supply-chain pipeline.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.