Thomson Reuters Breach, Pegasus Spyware and Node.js Attacks
Listen now
Stream the full 4:14 briefing here, and it keeps playing as you browse.
Prefer your own app?
In this briefing: 5 stories
Hacked dAily, the first AI-driven cybersecurity podcast from Cytadel Cyber, delivers a daily briefing for CISOs, security leaders, and decision-makers. Today’s episode covers five developments with direct implications for privacy, resilience, and enterprise risk:
- 01
Thomson Reuters reported unauthorized access to its C-Track court software, potentially exposing sensitive records from courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario. The incident highlights the risks of vendor cloud and backup environments, prompting password resets, access restrictions, investigations, and credit-monitoring measures.
- 02
China-linked hackers reportedly used USB devices to backdoor executives’ laptops, exploiting security fixes that organizations had not yet deployed. The campaign shows how basic physical access and delayed patching can bypass mature defenses and compromise high-value business environments.
- 03
Serbian student protesters and civil society figures were targeted with Pegasus and NoviSpy spyware, including a zero-click iPhone infection. The documented activity raises serious concerns about surveillance of political dissent, privacy, due process, and election-related interference.
- 04
Microsoft researchers identified a phishing campaign using invisible Unicode characters to disguise finance-themed lures and evade email filters. The activity demonstrates how AI-era obfuscation techniques can expose weaknesses in keyword, normalization, and content-detection pipelines.
- 05
Threat actors are abusing the trusted Node.js runtime to run scripts, maintain persistence, and deliver backdoors against government, technology, fintech, and hotel organizations. By combining legitimate tools, social engineering, commodity malware, and blockchain infrastructure, attackers are making detection and disruption more difficult.
Hacked dAily turns the day’s most important cyber developments into clear, actionable insight, published daily by Cytadel Cyber.