Berlin Ransomware, Avast Zero-Days and Condé Nast Data Sale
Listen now
Stream the full 4:17 briefing here, and it keeps playing as you browse.
Prefer your own app?
In this briefing: 5 stories
Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily. Built for CISOs, security leaders and executives, it delivers concise analysis of the threats shaping business risk.
- 01
Berlin officials say the Rhysida ransomware group has published data stolen after the city refused a €2 million demand. The leak may expose information on employees, citizens, businesses and emergency planning, highlighting the serious privacy and continuity risks facing public institutions, even when ransom is not paid.
- 02
Researcher Nightmare Eclipse has released three zero-day exploits targeting Avast, CrowdStrike and Nvidia, following a recent Kaspersky privilege-escalation disclosure. The activity shows that vulnerabilities in widely deployed security and enterprise products can create high-impact risks while vendors investigate and issue fixes.
- 03
Data linked to a reported 32.8 million Condé Nast accounts is being offered on a Russian-language cybercrime forum for $15,000. Although passwords and payment data reportedly are absent, names, email and postal addresses could support targeted phishing, fraud and impersonation across major publications.
- 04
Threat hunters report an extortion campaign impersonating IT help desks to trick executives into approving fake Microsoft 365 and SaaS logins. By stealing session tokens and accessing SharePoint, OneDrive, Exchange and Box, attackers can quietly extract sensitive data without malware or traditional lateral movement.
- 05
Researchers have uncovered PEEP, a post-compromise toolkit that disguises itself as a browser bookmarks extension and turns Chrome and Edge into persistent backdoors. It can steal cookies, history and session data while enabling remote commands, demonstrating how trusted browser processes can extend an intrusion into full endpoint access.