PATCHCORD Espionage, Threema DDoS and SafePal Data Leak
Listen now
Stream the full 4:13 briefing here, and it keeps playing as you browse.
Prefer your own app?
In this briefing: 5 stories
Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily. We deliver concise, credible intelligence for CISOs, security leaders, and executives.
- 01
Researchers linked the PATCHCORD espionage campaign to suspected APT36 activity after it targeted Afghan telecom providers and South Asian critical infrastructure with fake VPN installers and telecom tools. Its stealthy persistence and use of trusted cloud services raise significant risks for government and infrastructure networks.
- 02
Secure messaging provider Threema suffered multiple large-scale DDoS attacks, causing severe disruption across several countries and affecting its colocation partner. The incident highlights the operational and availability risks facing privacy-focused communication services.
- 03
SafePal reported that a flaw in its order-tracking system exposed data belonging to nearly 40,000 customers, including contact, shipping, and purchase details. Although wallets and financial credentials were not affected, the information could support targeted phishing and social engineering, with the data reportedly offered for sale.
- 04
Google is allowing users to remove visible watermarks from AI-generated media while retaining invisible SynthID and C2PA markers. The move supports creative workflows but makes synthetic content harder for the public to identify without dedicated detection tools.
- 05
The ASCII Group has reportedly been claimed as a victim by a ransomware operation alleging data theft and operational disruption. The case reinforces ransomware’s combined business continuity, legal, financial, and reputational risks for organizations.