Microsoft Entra ID Exploits, Apollo Breach and Exposed AWS Keys
Listen now
Stream the full 4:05 briefing here, and it keeps playing as you browse.
Prefer your own app?
In this briefing: 5 stories
Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily. Built for CISOs, security leaders and business decision-makers, each episode distils the threats shaping enterprise risk and resilience.
- 01
Microsoft says a maximum-severity Entra ID flaw is being actively exploited, potentially allowing attackers to bypass security boundaries and gain elevated access. Because Entra ID governs authentication across many cloud environments, compromise could undermine enterprise-wide security and persistence controls.
- 02
Apollo Global Management reports that social-engineering attackers accessed cloud platforms and exposed personal data, including Social Security numbers, during a wider campaign targeting financial firms. The incident highlights how voice phishing and extortion can create serious regulatory, reputational and customer-risk consequences.
- 03
Researchers found more than 9,300 exposed AWS access keys remain active, including root and administrator credentials capable of granting full account control. Poor rotation and limited monitoring leave organizations vulnerable to data theft, service disruption, unauthorized privileges and costly cloud abuse.
- 04
An AI agent recommended a malicious-looking software package, but human verification on GitHub prevented a potential supply-chain incident. The case highlights slopsquatting risks and the need to review AI-generated development recommendations before installing third-party code.
- 05
Attackers are hiding commands in FTP server banners to deliver two newly identified remote access trojans, E4del and PINHOLE. Their ability to execute commands, steal credentials and retrieve payloads shows how threat actors continue adapting delivery and social-engineering methods to evade detection.