Skip to content
Hacked dAily
4:11 listen

Pentagon Breach, Microsoft Star Blizzard and AI-Powered Malware Attacks

Hacked dAily

Listen now

Stream the full 4:11 briefing here, and it keeps playing as you browse.

In this briefing: 5 stories

Hacked dAily is the first AI-driven cybersecurity podcast from Cytadel Cyber, published daily for CISOs, security leaders and executives. Today’s briefing covers five developments shaping cyber risk and resilience.

  1. 01

    Pentagon data exposure

  2. 02

    Star Blizzard espionage campaign

  3. 03

    Security checks and user friction

  4. 04

    Malicious ChatGPT variants

  5. 05

    TeamFiltration targets Microsoft 365

The Defense Manpower Data Center is notifying 2.76 million living and 294,000 deceased individuals after unauthorized users accessed an unencrypted file-sharing server for about nine months. Exposed records included Social Security numbers and military-related details, creating significant identity, privacy and national-security concerns despite no known misuse.

Microsoft says the Russian intelligence-linked group Star Blizzard used fake event invitations to target more than 100 organizations, mainly in the United States and United Kingdom. The campaign highlights an evolving threat to governments, nonprofits and Ukraine-focused policy groups, with risks including credential theft and system compromise.

A security verification page temporarily blocked access while visitors enabled JavaScript and cookies, illustrating how publishers use layered defenses against bots and abuse. For businesses, stronger web protection must be balanced against customer friction, accessibility and lost engagement.

Researchers say malicious custom ChatGPT variants promoted through Google ads redirected users to fake backup sites, where ClickFix-style prompts persuaded them to run PowerShell commands installing remote-access malware. The campaign shows how trusted AI platforms can amplify social engineering, enabling attackers to steal data, monitor devices and maintain persistence.

Proofpoint says a TeamFiltration campaign targeted more than 5,700 Microsoft 365 accounts across 28 Latin American tenants, with confirmed compromises involving unmanaged service accounts lacking MFA and using likely default passwords. The activity demonstrates how forgotten accounts can provide direct access to VPNs, Azure and SharePoint, and why account hygiene and identity controls remain business-critical.

Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.