Skip to content
Hacked dAily
4:01 listen

Brevo Hack, Microsoft Police Data Risks, HEIF Heist and Settra Ransomware

Hacked dAily

Listen now

Stream the full 4:01 briefing here, and it keeps playing as you browse.

In this briefing: 5 stories

Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily. Built for CISOs, security leaders, and executives, each episode distils the developments shaping cyber risk, resilience, and business decision-making.

  1. 01

    Brevo Supply Chain Attack

  2. 02

    UK Police Data and Cloud Sovereignty

  3. 03

    HEIF Heist Vulnerabilities

  4. 04

    Government Impersonation Scams

  5. 05

    Settra Ransomware Targets Retail and Manufacturing

A compromised Cloudflare API key allowed malicious scripts to reach Brevo properties and customer-embedded JavaScript, potentially affecting more than 100,000 websites. Fake verification prompts and possible unauthorized WordPress plugin installs show how one vendor compromise can spread malware and social-engineering risk at scale.

A Guardian investigation found sensitive police records, victim statements, and internal emails from more than 40 forces stored on Microsoft cloud systems previously flagged as vulnerable to foreign access. The findings raise major questions about data sovereignty, cloud governance, and whether protections for highly sensitive public-safety information are sufficient.

Researchers disclosed flaws in widely used image-decoding libraries that could enable data theft, memory corruption, and remote code execution across platforms and enterprise services. Because AI and cloud systems depend on these libraries, unpatched versions could expose accounts, tokens, repositories, and user data.

FBI data shows fake police and government scams have caused more than $1.6 billion in losses since January 2025, with nearly 61,000 complaints. Threats involving arrest, jury duty, or licensing demonstrate why staff and customers must independently verify urgent demands for payment or sensitive information.

Huntress reports attacks using the Settra ransomware variant against retail and manufacturing organizations, with adversaries abusing remote tools, disabling recovery options, and deploying a vulnerable driver. The activity highlights how ransomware groups are strengthening post-compromise tactics to delay recovery and increase double-extortion pressure.

Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.