Cisco Zero-Days, HBO Max Malvertising and DDRop Hardware Attacks
Listen now
Stream the full 3:43 briefing here, and it keeps playing as you browse.
Prefer your own app?
In this briefing: 5 stories
Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily. Designed for CISOs, security leaders, and executives, each episode explains the threats shaping business risk and security decisions. Today’s five stories:
- 01
Cisco warns that a critical Secure Email Gateway zero-day is being actively exploited, allowing unauthenticated attackers to execute commands with full privileges. The flaw affects physical and virtual systems, and CISA’s emergency listing highlights the urgent risk to organizations relying on email security controls.
- 02
Russia-linked Sandworm is exploiting Cisco vulnerabilities to deploy Cyclops Blink, creating persistent access to edge devices. The campaign could support espionage or destructive operations, making urgent patching and compromise checks essential.
- 03
The official HBO Max Reddit account was hijacked to run more than 100 malicious ads targeting Windows and macOS users. The campaign used trusted channels and fake download pages to deliver information stealers and other malware, showing how social platforms can amplify credential theft.
- 04
ENISA warns that frontier AI is compressing the attack lifecycle, with vulnerabilities potentially weaponized within minutes and data stolen soon afterward. Organizations may need near-real-time detection, faster remediation, and carefully governed AI-assisted defense to keep pace.
- 05
Researchers disclosed DDRop, a hardware attack that can undermine confidential computing protections in systems from Intel and AMD. The finding raises serious concerns for cloud providers and sensitive workloads because it cannot be resolved through a simple software patch.