Skip to content
Hacked dAily
4:02 listen

| Gunra, Microsoft and Critical Infrastructure Under Siege

Hacked dAily

Listen now

Stream the full 4:02 briefing here, and it keeps playing as you browse.

In this briefing: 5 stories

Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily. Each episode delivers concise, executive-focused analysis of the threats shaping business risk, resilience and security strategy.

  1. 01

    Gunra ransomware targets critical infrastructure

  2. 02

    Iran-linked actors target U.S. water systems

  3. 03

    Storm-1175 exploits N-central software

  4. 04

    Kimsuky advances AI-assisted operations

  5. 05

    DeadLock signals a more resilient ransomware model

The FBI and South Korean police warn that the Gunra gang is exploiting firewall weaknesses to access, steal from and encrypt organizations in healthcare, finance, government and other major sectors. Its ransomware-as-a-service expansion and demands often exceeding $10 million increase pressure on critical infrastructure and public-sector leaders.

Cyberattacks against water and wastewater operators have spread across multiple U.S. states, with investigators increasingly suspecting Iranian-linked groups. The campaign highlights the operational and public-safety risks facing essential services with limited security resources.

Microsoft says China-linked Storm-1175 is exploiting a critical flaw in N-central to deploy StormEncryptor ransomware through managed service providers and their customers. The campaign creates a supply-chain risk capable of affecting many downstream organizations, including those that have not yet applied emergency fixes.

South Korean researchers report that North Korea’s Kimsuky group is using offline AI tools to support phishing and malware development. More convincing lures could make attacks harder to detect, increasing the importance of monitoring behavior, network activity and payload execution.

Microsoft identifies DeadLock as an emerging operation with more than 80 victims across sectors and regions. Its double-extortion approach and resilient communications infrastructure show how ransomware groups are building harder-to-disrupt operations beyond basic file encryption.

Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.