Skip to content
Hacked dAily
All Episodes

Hacked dAily Episodes

Every episode of Hacked dAily: 500 daily cybersecurity briefings and counting. Breaking news on breaches, ransomware and AI threats. Page 1 of 21.

The rundown

  1. 1 TrapDoor Supply Chain Attack: Threat actors spread credential-stealing malware via npm, PyPI, and CratesIO, exploiting open-source vulnerabilities and compromising developer environments. This highlights the urgent need for enhanced supply chain security protocols.
  2. 2 Verizon 2026 Data Breach Report: The report shows a rise in cyberattacks, especially phishing and ransomware, stressing the need for stronger cybersecurity frameworks and employee training to protect sensitive data and maintain business continuity.
  3. 3 Victorian Newspaper Ransomware Attack: A regional newspaper has been hit by a ransomware attack, disrupting operations and exposing vulnerabilities in smaller media outlets' cybersecurity, calling for improved protective measures.

+2 more stories

Open briefing →

The rundown

  1. 1 Dutch authorities have confiscated 800 servers from a Netherlands-based hosting provider known for facilitating cyberattacks. This marks a pivotal effort to dismantle the infrastructure supporting global cybercrime networks, highlighting the need for international collaboration in cybersecurity.
  2. 2 The cybercrime group Void Dokkaebi has developed a stealthy new malware called InvisibleFerret using Cython, boosting its evasion capabilities. This evolution in cyber tactics calls for more sophisticated security strategies to protect against elusive threats.
  3. 3 Grafana Labs will cease support for its open-source platform, Ghost, effective October 31, 2023, channeling focus toward primary products. This move could impact users relying on Ghost for monitoring solutions, emphasizing a shift in resource allocation within the enterprise landscape.

+3 more stories

Open briefing →

The rundown

  1. 1 Chinese hacker group Webworm exploits Discord and Microsoft Graph to breach European government networks, reflecting the increasing sophistication of attacks using legitimate platforms and urging stronger protective measures.
  2. 2 Canadian Jacob Butler, leader of the Kimwolf botnet compromising over 2 million Android devices, was arrested in Ottawa. Despite the seizure, Kimwolf's continued operation highlights persisting IoT vulnerabilities, threatening security across sectors.
  3. 3 Authorities dismantled "First VPN," a service aiding ransomware attacks by facilitating anonymity for criminals. This significant enforcement step stresses the value of global cooperation to combat cybercrime infrastructure.

+3 more stories

Open briefing →

The rundown

  1. 1 Grafana Labs' recent targeted cyberattack has exposed major vulnerabilities in supply chain dependencies, emphasizing the urgent need for stronger cybersecurity to safeguard proprietary data and open-source components.
  2. 2 In a landmark legal development, federal authorities have made the first arrests under a law against 'deepfakes' misuse in Brooklyn, underscoring the necessity of legal structures to protect against AI-driven digital misinformation.
  3. 3 The newly discovered ransomware strain, WantToCry, is exploiting SMB vulnerabilities to encrypt remote files, highlighting the critical importance of patches and cybersecurity protocols in safeguarding business data.

+2 more stories

Open briefing →

The rundown

  1. 1 GitHub finds itself under scrutiny after TeamPCP claims to have hacked its internal repositories, allegedly extracting sensitive data and demanding ransom. This breach underscores the vulnerabilities lurking in tech infrastructure, highlighting the urgent need for enhanced security measures to protect digital assets.
  2. 2 The Cybersecurity and Infrastructure Security Agency (CISA) faces backlash following the accidental exposure of sensitive credential data on GitHub. This significant leak has prompted demands for a thorough investigation into CISA’s internal security practices, especially as the U.S. grapples with heightened cybersecurity threats.
  3. 3 Stay tuned to Hacked dAily for insightful analysis and the latest developments in cybersecurity tailored for leaders who need to stay one step ahead.
Open briefing →

The rundown

  1. 1 Today's top story highlights INTERPOL's Operation Ramz, which arrested 201 individuals in a massive MENA region crackdown on cybercrime, demonstrating the critical importance and success of international cooperation in disrupting phishing scams and malware networks.
  2. 2 Next, security researchers unveil GhostTree, a path manipulation technique that bypasses Windows defenses, emphasizing an urgent need for updating enterprise security measures to counteract potential unauthorized access exploits.
  3. 3 Verizon's Data Breach Investigations Report shows exploited vulnerabilities now account for 31% of breaches, up from 20%, with a concerning gap in handling critical vulnerabilities, while ransomware tactics evolve with fewer victims choosing to pay attackers.

+2 more stories

Open briefing →

The rundown

  1. 1 A security flaw in the Funnel Builder WooCommerce plugin is actively exploited for checkout skimming, compromising customer payment data and underscoring the urgency of regular updates to e-commerce platforms.
  2. 2 Grafana Labs reported a breach involving the theft of source code but refused to pay ransom, highlighting the critical need to strengthen intellectual property protection and cybersecurity strategies.
  3. 3 OtterCookie, a new JavaScript and Node.js tool, has evolved from credential theft to active surveillance, delivered via npm and Vercel, posing significant data privacy risks.

+2 more stories

Open briefing →

The rundown

  1. 1 A deep dive into a vishing extortion operation uncovers cybercriminals adeptly exploiting phone-based fraud to trick victims and steal sensitive information. This emphasizes the need for upgraded vigilance and effective employee training against sophisticated voice-based threats.
  2. 2 The Fragnesia vulnerability (CVE-2026-46300) in Linux systems is a severe security risk, enabling unauthorized root access across multiple distributions. Organizations must urgently reassess protocols and deploy patches to protect critical systems and data.
  3. 3 PoC code for a critical NGINX vulnerability has been released, risking widespread code execution exploits. With NGINX's vast usage, swift system updates are crucial to maintaining security and operational integrity globally.

+3 more stories

Open briefing →

The rundown

  1. 1 Microsoft is boosting system security by automatically rolling back faulty Windows drivers, minimizing vulnerabilities and ensuring operational stability for users and enterprises.
  2. 2 VELVET CHOLLIMA, a new malware threat employing a fake trading app, emphasizes the rising complexity of cyberattacks, urging increased cybersecurity vigilance in the trading sector.
  3. 3 On Pwn2Own Berlin 2026's first day, experts unveiled 24 zero-day vulnerabilities, focusing on AI products and awarding $523,000 in bounties, showcasing the critical role of such events in preemptive cyber defense.

+3 more stories

Open briefing →

The rundown

  1. 1 Our top story reveals new zero-day vulnerabilities, YellowKey and GreenPlasma, in Windows OS, enabling potential code execution and privilege escalation. This discovery emphasizes the urgent need for rapid patches and vigilant system defenses.
  2. 2 In financial tech news, Abrigo suffered a breach affecting over 711,000 accounts, highlighting the increasing threats in fintech. Financial institutions must take proactive steps to fortify their cybersecurity frameworks to protect sensitive client data.
  3. 3 A cyber campaign, VELVET CHOLLIMA, uses a trading app as bait to deploy infostealer malware, showcasing sophisticated tactics by cybercriminals. Organizations are urged to rigorously vet apps and enhance security postures against such ploys.

+3 more stories

Open briefing →

The rundown

  1. 1 Texas Attorney General Ken Paxton has sued Netflix for allegedly collecting and selling user data without consent, potentially reshaping data privacy standards across streaming services and affecting Netflix's targeted advertising strategies, especially for minors.
  2. 2 Instructure settled with the ShinyHunters group following a breach that compromised educational data, prompting scrutiny by the U.S. House Committee on Homeland Security and raising concerns about data security in educational tech.
  3. 3 Ukraine's security officials linked a cyber-espionage operation to Russia's Gamaredon group, underscoring the need for heightened cyber defenses against evolving state-sponsored threats in geopolitical conflicts.

+3 more stories

Open briefing →

The rundown

  1. 1 Analysts have exposed a new CRPx0 malware vector targeting users with fake OnlyFans offers. This technique highlights the evolving threat landscape, emphasizing the need for robust security strategies to protect sensitive data.
  2. 2 The Nitrogen ransomware group targeted Foxconn, claiming 8 terabytes of data from their Wisconsin plant. This spotlight on data security urges corporations to enhance protective measures against breaches.
  3. 3 A supply chain attack hit TanStack, Mistral AI, and UiPath, revealing vulnerabilities in tech vendor ecosystems. Companies must reassess supply chain security to combat growing third-party risks.

+2 more stories

Open briefing →

The rundown

  1. 1 A newly found Linux flaw, tagged "Dirty Frag," poses significant risks to enterprise systems due to its potential to let attackers bypass security through fragmented IP packets. Organizations must urgently examine their defenses against this emerging threat.
  2. 2 Skoda Auto's online shop suffered a data breach exposing personal customer data, emphasizing the critical need for robust cybersecurity as automakers extend their digital services.
  3. 3 BWH Hotels faced a data breach compromising six months of personal and reservation details, reflecting the vulnerabilities in third-party managed systems and the necessity for stringent safeguards in handling sensitive data.

+3 more stories

Open briefing →

The rundown

  1. 1 Hackers are leveraging Google ads and Claude.ai chats to spread macOS malware, raising urgency for improved ad security and vetting for safer user interactions.
  2. 2 Cybercriminals manipulated DigiCert to obtain legitimate digital certificates, using them to legitimize malware and evade detection, stressing the need for stronger certificate validation protocols.
  3. 3 The shutdown of the Crimenetwork marketplace following the arrest of its administrator marks a key victory in combatting cybercrime, disrupting illicit trade and curtailing data theft operations.

+3 more stories

Open briefing →

The rundown

  1. 1 First, cybersecurity experts reveal CallPhantom, a fraud scheme exploiting fake Android apps to deceive millions in Asia-Pacific via the Google Play Store. This highlights the pressing need for vigilant security in mobile and payment sectors.
  2. 2 In our second story, cybercriminals masquerade harmful malware as Microsoft Teams installers, deploying a multi-stage loader to install backdoors. This emphasizes the necessity for organizations to validate software provenance to thwart breaches.
  3. 3 Next, JDownloader's website breach replaced software installers with a RAT-laden version, posing severe risks through unauthorized system access. This incident underscores the significance of strong supply chain security.

+3 more stories

Open briefing →

The rundown

  1. 1 In our top story, nearly 197,000 Zara customers are impacted by a data breach linked to ShinyHunters after a former Inditex provider was compromised. This breach underlines third-party vendor vulnerabilities and the interconnected risks faced by global retail brands.
  2. 2 Meta surprises industry-watchers by discontinuing encrypted Instagram Direct Messages, focusing on WhatsApp for secure chats. This shift sparks concerns about user safety, as privacy advocates challenge Meta's motives amid government pressures.
  3. 3 The discovery of “Bleeding Llama,” a critical unauthenticated memory leak vulnerability in Ollama, poses serious data integrity threats. This highlights the urgent need for strong security measures to protect organizations from potential exploits.

+3 more stories

Open briefing →

The rundown

  1. 1 Woflow Data Breach: Woflow's data breach affects 447,593 accounts, spotlighting vulnerabilities in handling sensitive business data. This calls for stringent cybersecurity enhancements in sectors managing personal information.
  2. 2 Google Chrome Privacy Concerns: Google Chrome allegedly installs a 4GB AI model without user consent, raising privacy red flags. This accentuates the importance of transparency and user rights in the AI adoption race.
  3. 3 Fake Claude AI Malware Threat: Hackers use a fake Claude AI website to deploy Beagle malware, posing data theft and operational risks. This highlights the importance of vigilance and strict security protocols to counter sophisticated cyber threats.

+2 more stories

Open briefing →

The rundown

  1. 1 Pitney Bowes' recent breach exposed 8.2 million business email records through a phishing attack. Linked to ShinyHunters, this incident highlights the persistent threat of cybercrime and the imperative of securing digital infrastructures.
  2. 2 A hacker's social engineering attack on Grok revealed vulnerabilities beyond technical aspects. This underscores the critical importance of employee training to counter manipulative tactics in cyber breaches.
  3. 3 PyTorch Lightning’s compromised update raises red flags about AI supply chain security. Incorporated by users unknowingly, it underscores the urgency for robust security protocols in software development against such threats.

+2 more stories

Open briefing →

The rundown

  1. 1 Top Story: Vimeo confirmed a data breach affecting 119,000 users due to a third-party vendor vulnerability. Exposed information includes user names, email addresses, and hashed passwords. This highlights the necessity for robust vendor security management in interconnected systems.
  2. 2 Mindgard researchers uncovered vulnerabilities in the AI assistant Claude, bypassing restrictions to obtain prohibited content. This poses significant risks regarding the manipulation of AI models, urging a reevaluation of AI safety measures.
  3. 3 An anti-ICE site, GTFO ICE, inadvertently exposed the personal data of 17,000 activists, including names and addresses. Such breaches emphasize the critical need for secure digital infrastructures in activist platforms, especially in politically charged environments.

+2 more stories

Open briefing →

The rundown

  1. 1 In a pivotal case, two former cybersecurity experts have been sentenced to four years for orchestrating ransomware attacks, spotlighting the severe insider threat posed when seasoned professionals go rogue.
  2. 2 OpenClaw's recent breach, compromising 135,000 instances, exposes severe security vulnerabilities, urging organizations to fortify defenses and align risk management strategies to prevent data exposure and restore trust.
  3. 3 Children fooling age verification systems with fake mustaches reveals glaring flaws in current facial recognition technologies, necessitating improved verification methods to protect minors online.

+3 more stories

Open briefing →

The rundown

  1. 1 Today, cybersecurity researchers have identified a malicious PHP package, 'intercom,' spreading a miniature Shai-Hulud attack variant via Packagist. This supply chain threat underlines the critical need for rigorous scrutiny of third-party components, as it can lead to software dependencies being compromised.
  2. 2 Instructure, the edtech firm behind Canvas, discloses a data breach with hackers threatening data leaks. This incident highlights significant privacy risks and the imperative of robust data protection measures within the digital education arena.
  3. 3 The US Military has partnered with seven tech companies to integrate AI into classified systems, accelerating national security modernization. This venture illustrates AI's growing strategic importance and its role in maintaining a technological edge.

+3 more stories

Open briefing →

The rundown

  1. 1 Today, ShinyHunters claims a breach of NVIDIA's GeForce NOW user data, potentially exposing critical details like emails and 2FA metadata. This unconfirmed event highlights heightened risks of phishing and account takeovers, calling for user vigilance.
  2. 2 Trellix faces unauthorized access to its source code repository but reports no misuse, focusing on intellectual property threats and supply chain risks. Their response underscores the importance of readiness in addressing cyber intrusions.
  3. 3 The discovery of the Deep#Door Trojan targeting Windows systems showcases advanced evasion techniques, signifying complex threats that demand robust, adaptive security measures to maintain data and operational safety.

+3 more stories

Open briefing →

The rundown

  1. 1 Today, we uncover a phishing campaign exploiting Google AppSheet that compromised 30,000 Facebook accounts, revealing significant data security vulnerabilities and emphasizing the need for improved phishing awareness and robust detection strategies.
  2. 2 Discover how Jerry's Store, a card-checking service, accidentally exposed 345,000 stolen card records due to poorly secured AI-generated code, highlighting the sophistication and flaws in cybercriminal marketplaces and raising alarms over data spread and identity theft.
  3. 3 We examine a critical cPanel vulnerability that allows attackers to bypass logins and potentially gain root access, presenting substantial risks to website integrity and data security, underscoring the necessity for timely security patches.

+3 more stories

Open briefing →

The rundown

  1. 1 In our top story, a surge in AI-generated celebrity deepfake scams on TikTok raises alarms over their sophistication and impact on digital trust. These fraudulent videos are increasingly used for scams, challenging verification mechanisms and urging stronger public awareness.
  2. 2 Next, we expose a phishing scheme exploiting PayPal's email service, deceiving users with fake tech support prompts. This tactic highlights the dangers of manipulated communications and the need for vigilant security checks to protect personal banking information.
  3. 3 Turning to AI security, breaches targeting coding assistants like Claude Code reveal the persistent threat of credential theft. This emphasizes the necessity for robust security in AI environments to prevent misuse as these tools gain popularity across industries.

+3 more stories

Open briefing →
Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.