Article archive
Complete list of articles from the Chors.net blog in English. All posts on cybersecurity, AI, and digital risk for businesses.
- NIS2 penalties in 2026: what you really risk
- Does my company fall under NIS2? Qualification in 5 steps
- CVE-2026-33824: double-free in Windows IKE = RCE risk
- CVE-2025-60710 in Windows Task Host: ransomware threat
- Defender "ShieldBreak" (CVE-2026-69414): zero-day EoP
- Medusa Ransomware (CISA AA25-071A): 500+ victims, 24h exploit
- ToolShell/Warlock: supply-chain attack on on-prem SharePoint
- CVE-2026-55040 SharePoint auth bypass: act in 24h
- MyDr breach: how a cyberattack on Polish medical software affects nearly 19M patients — and what it means for your business
- How does Zenity's PleaseFix turn ChatGPT Atlas and Claude in Chrome into zero-click account-takeover tools?
- Is your WordPress login screen exposing you to unauthenticated XSS-to-RCE via CVE-2026-64638?
- Is PLM the new enterprise attack surface? What CVE-2026-12569 in Windchill and FlexPLM means for production
- Wesco (Fortune 500) confirms incident in cloud CRM — ExfilSquad claims 2.6M records stolen. What does this mean for a B2B company that keeps customers in the cloud?
- Iran-linked APT in 12 US states: are your water utilities (or B2B with similar OT) under attack right now?
- Can a stolen engineer account replace your Watchfire controller firmware? What CVE-2026-5846 means for facilities and OT
- What does the UK ICO reprimand of ACRO Criminal Records Office reveal about supply-chain patch management in 2026?
- Can a tampered DNA file reach a forensic report? What CVE-2026-17583 means for clinical and forensic labs
- Storm-1175 and StormEncryptor: can one compromised N-central RMM put hundreds of your customers at risk?
- Are SonicWall SMA1000 vulnerabilities (CVE-2026-15409 and CVE-2026-15410) a real risk for your organization — and what to do in 30/90 days?
- Are your Siemens SIMATIC S7-1500 MFP controllers running a 5-year Linux-kernel backlog? What ICSA-26-209-04 means for production
- Can your building management system be crashed through OpenSSL? What CVE-2025-15467 in Siemens Desigo CC means for facility OT
- Can a single CIP packet stop your CompactLogix line? What CVE-2026-9636 means for Rockwell ControlLogix / CompactLogix
- Is your OPC UA server exposed by open62541 flaws? What CVE-2026-63362 / CVE-2026-65423 / CVE-2026-63035 mean for IIoT and SCADA
- Can a single crafted IEC 61850 packet crash your protection relays? What CVE-2026-66720 / CVE-2026-66369 / CVE-2026-63550 mean for substations
- Can a crafted IEC 104 frame crash an OT master? What CVE-2026-61893 and CVE-2026-63033 mean for EU substations and SCADA
- Can someone tamper with your CC-Link IE TSN traffic? What CVE-2026-13584 means for time-sensitive manufacturing
- Can someone steal your MikroTik WireGuard private key? What CVE-2026-14227 means for site-to-site VPNs
- What happens when a government beneficial-ownership registry is breached? Lessons from the Liechtenstein VwbP cyberattack
- Lidl supplier IT breach — what really leaked and what should your company do?
- Is the AFD.sys zero-day (CVE-2026-68820) a real threat for manufacturing and defense companies?
- Are state-backed attackers inside your PLCs? What CISA AA26-097A means for industrial operators
- Gunra ransomware (CISA AA26-222A): what B2B and manufacturing must do in 30/90 days
- Is your GlobalProtect portal a Qilin affiliate's first move? What CVE-2026-0257 means for production networks
- CVE-2026-55040: critical SharePoint JWT authentication bypass — why the Rapid7 PoC triggered an exploitation wave and what it means for your on-prem
- SharePoint CVE-2026-58644 is now used by ransomware gangs — what it means for your on-prem estate
- Is your Microsoft SharePoint Server safe from ransomware today? (CVE-2026-45659, CISA KEV)
- Is your Cisco ASA / FTD with SSL VPN under a credible DoS attack today? (CVE-2026-20349, CISA BOD 26-04 dueDate: 2026-08-14)
- C-CURE 9000 & Victor (Johnson Controls): is unauthenticated RCE via .NET deserialization putting your access control at risk?
- Does opening an email let Russian attackers steal your mailbox? TA488 half-click XSS on Zimbra and OWA
- Why should you patch ABB Ability Zenon now? What ICSA-26-218-01 and its MongoDB vulnerabilities mean for ICS/SCADA
- WordPress CVE-2026-63030 — can an attacker take over your server without logging in?
- Is "don't click anything" still enough? The TA488 Zimbra XSS attack breaks every phishing rule
- Is a private APN a real attack vector into a Polish CHP plant — what CERT Polska's August 2026 report reveals about IT-OT risk?
- OpenAI pauses work on Astra after first Critical cybersecurity capability trigger under the Preparedness Framework — what it means for organizations running AI agents?
- ChainDrop: over 1,300 npm packages compromised by a self-propagating worm — what it means for your business
- SBOM Minimum Elements 2026 — CISA and 16 partner agencies updated software supply chain requirements. What does this change for your business?
- Is your Exchange Outlook Web Access already compromised by the Russian OWAReaper campaign (CVE-2026-42897)?
- Is your Metabase 1.58+ installation leaking customer data right now?
- Can a single click on a link leak Jira and Confluence data through an AI assistant?
- Is your Progress LoadMaster on CISA's KEV list today? What CVE-2026-8037 means for internet-exposed ADC
- NIS2 certification — myth vs fact: why the "NIS2 certificate" does not exist
- How to report NIS2 in Poland — KSC registry self-registration step by step (deadline 3.10.2026)
- What is NIS2 — Directive 2022/2555, Polish transposition (KSC 2026) and how it differs from NIS1
- CISA added 3 actively exploited flaws (Langflow, N-central, Tomcat) to KEV — is your stack on the list?
- Is your CI/CD pipeline exposed to unauthenticated RCE via JetBrains TeamCity CVE-2026-63077?
- AI agents took unsanctioned real-world actions in cyber tests — what does it mean for your business?
- Zabka breached through a supplier account — what actually leaked and what should your company do?
- Can a Word Document Quietly Alter Your Company’s Work?
- Can AI Agent Testing Put Your Company at Risk?
- Can an Autonomous AI Agent Increase Your Company's Cyberattack Risk?
- Can Your Business Detect Cybersecurity Risks Fast Enough in the AI Era?
- Can Your Company Respond Fast Enough When Attackers Use AI?
- Is Your Company Already a Target of ChatGPT Phishing Scams?
- Compromised Email Account Used for Phishing: An Analysis of the DKWOC Incident
- Can Your AI Agent Leak Company Secrets Without You Knowing?
- Can One Cloud Misconfiguration Expose Cameras, Office Maps, and Wi‑Fi Passwords?
- Can Your Business Withstand Autonomous AI-Driven Attacks?
- Can Your Business Trust an AI Agent That Finds Tools on GitHub by Itself?
- Can You Trust Your AI Agent to Follow Company Rules?
- Can Your Business Survive an AI That Finds Zero-Days in 27 Minutes?
- Is Your Company Ready for an AI Agent That Finds — or Exploits — Code Vulnerabilities on Its Own?
- Can your company survive its own artificial intelligence? The OpenAI and Hugging Face case
- Can Your Company's Zimbra Email Be Compromised Just by Viewing an Email?
- Can a Single Local Linux Flaw Give an Attacker Root Access to a Server?
- Is MFA Enough to Protect Microsoft 365 from Phishing?
- Can an AI agent put your company at risk before it saves time? 7 controls before automation
- Can a critical WordPress vulnerability put your company’s revenue and reputation at risk?
- AI Hacked AI: Analysis of the OpenAI x Hugging Face Security Incident and B2B Security Implications
- Commerce under AI bot pressure: what the Akamai report means for businesses and online stores
- Microsoft, AI security, and the new reality of business cyber risk
- WordPress critical vulnerabilities: how to assess your business risk in 30 minutes
- AI builds malware faster than humans? What the TuxBot v3 Evolution case teaches businesses
- Airbnb CEO Brian Chesky and the X Account Compromise: what this incident teaches B2B companies about executive account security
- Chinese Hackers Use Claude Code and DeepSeek in Government Cyberattacks — What It Means for Manufacturing and B2B Companies
- AI Jailbreaks in 2026: Why Static LLM Guardrails Are No Longer Enough | Chors.net
- Nike and Alcon Data Breach 2026: What It Reveals About Your Company's Cyber Risk | Chors.net
- GigaWiper: The Frankenstein Windows Backdoor Manufacturing and SaaS Firms Need to Know About
- How the Ethereum Foundation Uses AI to Hunt Security Bugs — and What Every B2B Company Can Learn From It
- Russian Hackers Are Compromising Doorbell and IoT Cameras Near NATO Bases — What It Means for Your Company's Security
- AI financial advice as a new cyber risk. What inconsistent model outputs mean for E-E-A-T, SEO, and AI citation
- The AI Safety Index Summer 2026: Navigating Responsible AI for B2B, Cybersecurity, and Governance
- The Rogue Agent in Google Dialogflow CX: Lessons for Companies Running AI Chatbots
- Tata Electronics Leak, iPhone 18 Pro Prices, and the AI Boom: A Supply Chain Security Crisis Unveiled
- How to Protect Your Company from Hackers and AI Attacks – Lessons from the Pegasus Case (2026)
- Cybersecurity 2026: how to protect your business and website from AI-driven attacks
- How to Protect Your Company from AI-Driven Attacks
- JADEPUFFER: The First Autonomous AI Ransomware and What It Means for Your Business