Bitget Breach, GitLab Leaks, TeamCity Exploits and Salesforce AI Flaws
Listen now
Stream the full 3:52 briefing here, and it keeps playing as you browse.
Prefer your own app?
In this briefing: 5 stories
Hacked dAily is the first AI-driven cybersecurity podcast from Cytadel Cyber, published daily for CISOs, security leaders, and business decision-makers. Each episode delivers concise, credible analysis of the threats shaping enterprise risk.
- 01
Bitget crypto breach: Bitget suspects North Korean hackers stole approximately $351.6 million by abusing compromised backend systems, while cold wallets and private keys remained secure. Withdrawals are suspended, but the incident highlights the growing financial and geopolitical risk of state-linked cryptocurrency theft.
- 02
GitLab token exposure: Researchers found private GitLab email addresses published in READMEs and support pages, allowing attackers to submit changes or issues as trusted project owners. Exposed tokens could enable code tampering, access to secrets, and software supply-chain attacks; maintainers should remove and reset them.
- 03
TeamCity ransomware exploitation: CISA warned that ransomware groups are exploiting a critical JetBrains TeamCity authentication flaw that enables unauthorised command execution. Unpatched servers could expose credentials, build systems, and software pipelines, creating significant enterprise and supply-chain risk.
- 04
Salesforce Agentforce flaws: Three vulnerabilities allowed attackers to poison leads, manipulate AI agents, steal CRM data, and send phishing messages through Slack without user interaction. Salesforce has patched the issues, but the case shows the security and containment challenges of AI agents connected to sensitive business systems.
- 05
New EDR evasion technique: Researchers detailed Process Parameter Poisoning, which hides malicious code in normal Windows process startup fields to evade some EDR and XDR controls. The technique demonstrates why defenders need stronger visibility into process parameters, thread manipulation, and abnormal execution behavior.