Google Fined, Water Utilities Hacked, Fake LastPass Malware Attacks
Listen now
Stream the full 3:37 briefing here, and it keeps playing as you browse.
Prefer your own app?
In this briefing: 5 stories
Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily. Each episode delivers concise, credible analysis for CISOs, security leaders, and business decision-makers. Today’s briefing:
- 01
Water utilities targeted
- 02
Google fined €403 million
- 03
Fake LastPass Authenticator installer
- 04
Fake recruitment targets Rust developers
- 05
Malware hidden in PNG files
Attackers altered operational technology settings, pumping cycles, alarms, and remote access at two small Colorado water utilities. Service and public safety were unaffected, but the incident highlights the exposure of critical infrastructure controls and the potential impact of attacks on essential services.
Ireland’s Data Protection Commission fined Google over GDPR failures involving the collection, transparency, and retention of location data. Google says the issues relate to older policies, but the decision reinforces the compliance, privacy, and reputational risks of location analytics.
A malicious GitHub installer used a Microsoft-signed driver to disable security tools before stealing passwords, wallet data, and sessions. The campaign shows how attackers can abuse trusted signing chains and SEO tactics to bypass endpoint defenses.
The Rust project warned that attackers are using convincing job offers and company profiles to trick contributors into installing malware or executing commands. A compromised developer account or device could enable supply-chain attacks across the Rust package ecosystem.
Microsoft researchers found the TerminalFix campaign hiding an executable and a split DLL inside PNG files. The technique demonstrates how seemingly harmless images can carry malware and support multistage intrusions while challenging routine detection.