GitLab, Microsoft, Chess.com and Citrix Hit by Cyber Threats
Listen now
Stream the full 4:02 briefing here, and it keeps playing as you browse.
Prefer your own app?
In this briefing: 5 stories
Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily for CISOs, security leaders, and business decision-makers. Today’s briefing covers five developments with immediate security and business implications:
- 01
GitLab vulnerability under active attack: A critical path traversal flaw in the repository commits API could expose SSH keys, credentials, deploy tokens, and CI/CD variables without authentication. With exploitation attempts reported within 24 hours, organisations should patch urgently, restrict exposure, and review logs for suspicious file-path requests.
- 02
Chess.com data breach: A reported 2026 incident exposed user information from the major online platform. The breach highlights how consumer account data can fuel credential attacks, phishing, identity abuse, and reputational damage.
- 03
AI-powered financial fraud and cloud compromise: Microsoft reports more than one million fake CEO-approved payment emails, alongside campaigns using passkey-themed phishing and social engineering to hijack cloud tenants. The activity shows how attackers are combining AI-generated lures with MFA bypass and persistence techniques to enable fraud and data theft.
- 04
Warning over uncontrolled AI development: Anthropic CEO Dario Amodei is calling for greater caution, warning that advanced systems could enable agent swarms capable of overwhelming parts of the internet. His comments reflect growing concern that AI capabilities are advancing faster than governance, safety controls, and oversight.
- 05
Critical Citrix NetScaler authentication bypass: A high-severity SAML flaw can be triggered by a single unauthenticated request, with impact ranging from service disruption to internal proxying and potential root access. Organisations should patch affected appliances, retire end-of-life versions, and assess each virtual server separately.