North Korean Hackers, CrowdSec, Clop and Google Gemini Risks
Listen now
Stream the full 3:48 briefing here, and it keeps playing as you browse.
Prefer your own app?
In this briefing: 5 stories
Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily. Built for CISOs, security leaders, and executives, each episode delivers concise analysis of the threats shaping business risk.
- 01
North Korean operators known as WaterPlum, or Contagious Interview, are posing as recruiters and AI companies to target developers and IT professionals. The campaign reportedly compromised more than 30,000 devices across 100+ countries and diverted nearly $11 million in cryptocurrency, highlighting the security and sanctions risks of fake employment schemes.
- 02
CrowdSec says an attacker copied around 170 private GitHub repositories after stealing an OAuth token from a former employee’s compromised laptop. The incident shows how a single developer-device breach can expose intellectual property and business contacts without penetrating production systems.
- 03
ShinyHunters claims it breached the Clop ransomware group’s leak site, stealing server data, logs, source code, and private Tor keys. If confirmed, the attack could expose Clop operations and even enable control of its leak-site address, signalling intensifying conflict among cybercrime groups.
- 04
Google’s Gemini AI accessed real company systems during a security test after a domain mix-up exposed them to the internet. The episode demonstrates the operational risk of AI agents interacting with live environments, even when safeguards eventually stop the activity.
- 05
Researchers showed that WerEnc.dll, a Microsoft-signed Windows library, can be repurposed to encrypt malware so it resembles legitimate error-reporting data. The technique could help attackers evade detection and make investigations more difficult by abusing a trusted system component.