Skip to content
Hacked dAily

Cyber news, every weekday

Hacked dAily show artwork

Hacked dAily The world’s first AI-powered cybersecurity podcast

The breaches, ransomware and AI threats that matter, broken down every morning in under five minutes, for CISOs, executives and technologists.

On air Runtime 4:02 No. 558

Cisco, Bitget and OpenAI Face Zero-Days, Breaches and Covert Attacks

Show notes

The rundown · 5 stories

  1. 1 Cisco warns that attackers are actively exploiting CVE-2026-76504, a critical authentication…
  2. 2 Bitget says a $387.5 million cryptocurrency theft resulted from a zero-day in third-party…
  3. 3 A cyberattack disrupted South Africa’s air traffic control systems, forcing officials to use…
  4. 4 OpenAI says it disrupted an effort to extract proprietary reasoning capabilities from its models…
  5. 5 Researchers have identified Terminalfix and Lorem Ipsum Loader as tools supporting covert…

Created by Manit Sahib · Produced by Cytadel Cyber

Recent Briefings

Miss a morning? Catch up on the week.

All episodes

The rundown

  1. 1 Apple patched CVE-2026-86950, a CoreGraphics zero-day enabling arbitrary code execution through specially crafted files, after Meta identified possible exploitation against targeted individuals. The incident highlights the continuing risk of sophisticated, potentially zero-click attacks and the need for rapid patching across Apple fleets.
  2. 2 Researchers found more than 16,000 misconfigured Supabase databases exposing personal data, passwords, authentication tokens, and possibly payment information. The scale of the exposures underscores how weak access controls and poor cloud configuration can create significant privacy, fraud, and regulatory risks.
  3. 3 Japan’s Keio confirmed a ransomware attack that disrupted business systems. The incident reinforces the need for tested backups, rapid detection, and practiced response plans to limit downtime, recovery costs, and reputational damage.

+2 more stories

Open briefing →

The rundown

  1. 1 Citrix confirmed active exploitation of two critical zero-day remote-code-execution flaws in NetScaler ADC and Gateway, including some default configurations. Organizations should patch immediately, isolate exposed appliances, and investigate for earlier compromise, as fixes provide no assurance that attackers were not already present.
  2. 2 Microsoft reported active exploitation of a SharePoint vulnerability, CVE-2026-65660, roughly six weeks after patching and soon after technical details emerged. Attempts to deploy webshells have been observed, and its addition to CISA’s catalog increases pressure to patch and check servers for compromise.
  3. 3 Cloudflare fixed a cross-tenant flaw in its Containers and Sandboxes services that could have exposed residual data from other customers’ containers on shared hosts. Although no customer exposure was confirmed, the incident highlights the business and privacy risks of weakened isolation in managed cloud infrastructure.

+2 more stories

Open briefing →

The rundown

  1. 1 Top Story 1: No article content was available beyond a verification page, so there is no reliable story to report.
  2. 2 GitHub temporarily re-enabled two third-party Actions previously compromised in the Mini Shai-Hulud supply-chain campaign. Their mutable version tags still pointed to malicious code, potentially exposing tokens, credentials, and CI/CD secrets, highlighting the need to audit dependencies and rotate secrets after a suspected compromise.
  3. 3 China and the United States agreed to create a channel for AI-related incidents and improve military crisis communications. The limited progress could reduce escalation risks, while continued trade discussions may affect technology supply chains and broader business planning.

+2 more stories

Open briefing →

The rundown

  1. 1 Kiteworks has urged customers worldwide to shut down servers for six hours following credible law-enforcement intelligence suggesting an attack may be imminent. Although no breach is confirmed, the warning highlights the sensitivity of enterprise file-sharing platforms and their appeal to extortion groups.
  2. 2 U.S. Army soldier Cameron John Wagenius received 70 months in prison and nearly $295,000 in penalties for hacking telecom companies and stealing call and text metadata linked to more than 100 million AT&T customers. The case underlines the persistent insider-threat risk to telecommunications and government systems.
  3. 3 Microsoft has attributed a destructive Azure campaign to Storm-3168, which used compromised service identities to access and delete cloud resources and collect credentials. The activity demonstrates how exposed credentials and weak workload-identity controls can enable rapid cloud disruption, ransomware, and extortion.

+2 more stories

Open briefing →

The rundown

  1. 1 Bitget crypto breach: Bitget suspects North Korean hackers stole approximately $351.6 million by abusing compromised backend systems, while cold wallets and private keys remained secure. Withdrawals are suspended, but the incident highlights the growing financial and geopolitical risk of state-linked cryptocurrency theft.
  2. 2 GitLab token exposure: Researchers found private GitLab email addresses published in READMEs and support pages, allowing attackers to submit changes or issues as trusted project owners. Exposed tokens could enable code tampering, access to secrets, and software supply-chain attacks; maintainers should remove and reset them.
  3. 3 TeamCity ransomware exploitation: CISA warned that ransomware groups are exploiting a critical JetBrains TeamCity authentication flaw that enables unauthorised command execution. Unpatched servers could expose credentials, build systems, and software pipelines, creating significant enterprise and supply-chain risk.

+2 more stories

Open briefing →

558+

mornings of cyber news

Every Hacked dAily briefing, archived and searchable.

Browse the archive

Produced by Cytadel Cyber

The AI reading this news can also test your defences

Cytadel Cyber runs AI-enhanced red teaming: a real adversary, accelerated by AI, run safely against your organisation to show whether you survive. Founded by Manit Sahib, former Head of Red Teaming at the Bank of England and CBEST framework contributor.

Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.