Rust Crates Poisoned, N-able Vault Bug, LockBit Targets US Bank
Listen now
Stream the full 4:00 briefing here, and it keeps playing as you browse.
Prefer your own app?
In this briefing: 5 stories
Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily for CISOs, security leaders, and decision-makers. Today’s briefing covers five developments with implications for enterprise risk, resilience, and security strategy.
- 01
Rust supply-chain attack
- 02
N-able password vault flaw
- 03
LockBit claims US Bank breach
- 04
Cryptographic context injection targets AI
- 05
Zimbra flaw exploited in the wild
Hackers compromised the maintainer account for the popular arrayref crate and briefly poisoned it, along with append-only-vec and internment, to run malware during compilation. The campaign could steal credentials and host data across major operating systems, putting developers and projects in cryptography, blockchain, graphics, Ethereum, and Solana at risk; affected teams should assume compromise and rotate secrets.
N-able disclosed a vulnerability that could have exposed master keys in its password vault, potentially affecting managed service providers and their customers. Although the issue has been addressed and widespread exploitation was not reported, it demonstrates how one flaw in a centralized credential platform can create broad downstream exposure.
US Bank is investigating LockBit’s claim that it stole data and has issued a September 3 pay-or-leak deadline. The bank says there is no current indication of internal compromise, but the allegation highlights extortion risk, third-party exposure, and the pressure to validate controls and contain reputational damage.
Researchers demonstrated an attack that hides malicious instructions in encrypted content, potentially tricking Grok and other AI systems into revealing chats and personal data. The technique shows how routine summarization and assistance workflows can become data-exfiltration paths when guardrails fail to detect concealed threats.
CERT Polska reports active exploitation of CVE-2026-73570, a high-severity Zimbra flaw affecting deployments with optional SNMP features enabled. Unauthenticated attackers can execute commands, creating opportunities for persistence, email and credential theft, and deeper network compromise; organizations should patch urgently and review affected systems.