Kiteworks Warning, Microsoft Azure Attack and tac_plus RCE
Listen now
Stream the full 3:59 briefing here, and it keeps playing as you browse.
Prefer your own app?
In this briefing: 5 stories
Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily. Each episode distils the threats, incidents, and security decisions that matter most to CISOs, security leaders, and business executives. Today’s five stories:
- 01
Kiteworks has urged customers worldwide to shut down servers for six hours following credible law-enforcement intelligence suggesting an attack may be imminent. Although no breach is confirmed, the warning highlights the sensitivity of enterprise file-sharing platforms and their appeal to extortion groups.
- 02
U.S. Army soldier Cameron John Wagenius received 70 months in prison and nearly $295,000 in penalties for hacking telecom companies and stealing call and text metadata linked to more than 100 million AT&T customers. The case underlines the persistent insider-threat risk to telecommunications and government systems.
- 03
Microsoft has attributed a destructive Azure campaign to Storm-3168, which used compromised service identities to access and delete cloud resources and collect credentials. The activity demonstrates how exposed credentials and weak workload-identity controls can enable rapid cloud disruption, ransomware, and extortion.
- 04
The Carbonato botnet is stealing credentials and sensitive data, then using compromised access and AI-enabled infrastructure to support further attacks. The campaign shows how automation and AI-related services are helping criminals scale operations while making detection more difficult.
- 05
A critical flaw in the tac_plus TACACS+ daemon enables pre-authentication remote code execution and may allow attackers to recover shared secrets. A patch is available, but the vulnerability highlights the business and security risks of aging, poorly maintained software controlling administrative access across enterprise and critical networks.