Proofpoint, DeepSeek and Microsoft Face Escalating AI Cyberattacks
Listen now
Stream the full 4:24 briefing here, and it keeps playing as you browse.
Prefer your own app?
In this briefing: 5 stories
Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily. Built for CISOs, security leaders, and decision-makers, it delivers concise analysis of the threats shaping business risk.
- 01
China-aligned espionage groups, including APT31, rapidly chained three browser and Windows zero-days to target NGOs and organizations across aerospace, mining, manufacturing, consulting, and finance. The campaign enabled credential theft, browser surveillance, and deeper system access, highlighting the urgency of rapid patching and threat-informed monitoring.
- 02
U.S. agencies accuse six Chinese AI firms of industrial-scale efforts to extract knowledge from leading models including Claude, GPT, Gemini, and Grok. The alleged activity signals a growing AI security and geopolitical risk, potentially undermining the commercial advantage of frontier-model developers.
- 03
Infostealer logs are exposing replayable session tokens and AI-service API keys from providers including Google, Anthropic, and OpenAI. The access can bypass passwords and MFA, creating risks of account takeover, billing fraud, data exposure, and unauthorized enterprise AI use.
- 04
A new report warns that identity-based AI attacks are becoming a major enterprise threat, using stolen credentials and compromised accounts to blend into normal activity. Security leaders should strengthen identity controls, access governance, and behavioral monitoring to reduce exposure to fraud and data theft.
- 05
Microsoft is tracking campaigns using passkey-themed lures, impersonation, device-code attacks, and AiTM phishing to compromise Microsoft 365 identities. Attackers then enrolled MFA, accessed cloud APIs, and extracted data, showing how a helpdesk-style lure can become a persistent cloud intrusion.