Brevo Hack, Microsoft Police Data Risks, HEIF Heist and Settra Ransomware
Listen now
Stream the full 4:01 briefing here, and it keeps playing as you browse.
Prefer your own app?
In this briefing: 5 stories
Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily. Built for CISOs, security leaders, and executives, each episode distils the developments shaping cyber risk, resilience, and business decision-making.
- 01
Brevo Supply Chain Attack
- 02
UK Police Data and Cloud Sovereignty
- 03
HEIF Heist Vulnerabilities
- 04
Government Impersonation Scams
- 05
Settra Ransomware Targets Retail and Manufacturing
A compromised Cloudflare API key allowed malicious scripts to reach Brevo properties and customer-embedded JavaScript, potentially affecting more than 100,000 websites. Fake verification prompts and possible unauthorized WordPress plugin installs show how one vendor compromise can spread malware and social-engineering risk at scale.
A Guardian investigation found sensitive police records, victim statements, and internal emails from more than 40 forces stored on Microsoft cloud systems previously flagged as vulnerable to foreign access. The findings raise major questions about data sovereignty, cloud governance, and whether protections for highly sensitive public-safety information are sufficient.
Researchers disclosed flaws in widely used image-decoding libraries that could enable data theft, memory corruption, and remote code execution across platforms and enterprise services. Because AI and cloud systems depend on these libraries, unpatched versions could expose accounts, tokens, repositories, and user data.
FBI data shows fake police and government scams have caused more than $1.6 billion in losses since January 2025, with nearly 61,000 complaints. Threats involving arrest, jury duty, or licensing demonstrate why staff and customers must independently verify urgent demands for payment or sensitive information.
Huntress reports attacks using the Settra ransomware variant against retail and manufacturing organizations, with adversaries abusing remote tools, disabling recovery options, and deploying a vulnerable driver. The activity highlights how ransomware groups are strengthening post-compromise tactics to delay recovery and increase double-extortion pressure.