Ransom Cartel, Palo Alto, Microsoft Teams Attacks and KVM Zapscape
Listen now
Stream the full 4:18 briefing here, and it keeps playing as you browse.
Prefer your own app?
In this briefing: 5 stories
Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily. Each episode delivers concise, decision-ready analysis for CISOs, security leaders, and executives. Today’s five stories:
- 01
A longtime cybercriminal received a 16-year sentence for operating Ransom Cartel, which attacked at least 18 organizations and extorted $5.2 million. The case highlights the financial and operational damage that small, coordinated ransomware networks can inflict.
- 02
China has opened a national-security review of Palo Alto Networks products, citing critical-infrastructure protection and cyber risk. The probe could restrict the company’s access to the Chinese market and strengthen domestic competitors.
- 03
UNC6671, linked to the BlackFile extortion operation, targeted hedge funds and private-equity firms through helpdesk impersonation and stolen Microsoft 365 and Okta credentials. The campaign shows how social engineering can quickly escalate into cloud compromise and high-value extortion.
- 04
Sophos reports that STAC4749 used Microsoft Teams voice phishing and remote-access tools to compromise dozens of North American organizations. In at least three cases, attackers deployed Chaos ransomware within 17 hours, underscoring the speed of modern identity-led attacks.
- 05
A Linux KVM vulnerability known as Zapscape could allow attackers with root access inside an L1 virtual machine to escape to the host. Organizations using nested virtualization for untrusted workloads should patch promptly, as public proof-of-concept code demonstrates the potential for host-level compromise.