Skip to content
Hacked dAily
All Episodes

Hacked dAily Episodes

Every episode of Hacked dAily: 558 daily cybersecurity briefings and counting. Breaking news on breaches, ransomware and AI threats. Page 14 of 24.

The rundown

  1. 1 Today's workout-inspired exposé reveals a gym software company that’s letting it all hang out, with 1.6 million voicemail files leaked for a not-so-public workout (privacy sweat not included).
  2. 2 Next up, the Salt Typhoon cyber espionage plot has docked with 45 new domains revealed, proving once again that hackers make surprisingly good treasure hunters… or forgetful domain hoarders.
  3. 3 Plex induces a round of password change-up; that's "relationship goals" in the digital age, where server owners upgrade systems nonchalantly, as if they weren’t already part of an inevitable techno-speeding ticket.

+2 more stories

Open briefing →

The rundown

  1. 1 Next up, GPUGate gets cheeky by exploiting Google Ads for malware escapades, proving once again that trust is a currency better guarded than our most precious data. IT firms, brace yourselves because even algorithms can wear disguises better than your favorite spy flick heroes.
  2. 2 We then tiptoe into espionage with MostereRAT, whose stealthy malware antics leave everyone wondering if digital beekeeping might be the safer career path. It seems the cybercritters are getting sneakier each day!
  3. 3 Meanwhile, LockBit's latest release, version 5.0, is out, claiming it's a leaner, meaner, ransomware machine. But will it be a triumphant sequel or a flawed rerun?

+2 more stories

Open briefing →

The rundown

  1. 1 Meanwhile, Apple’s iCloud Calendar has found a new role as the go-to spam delivery service. Forget sleek design and perfect functionality, right now, it's serving up phishing emails like a pro. Apple's servers are indeed getting a not-so-glamorous reality check in spam school.
  2. 2 Buckle up for a tale from the East as Noisy Bear rolls out "BarrelFire," targeting Kazakhstan's energy sector in a phishing campaign. It's like Die Hard, but with fewer explosions and more...email links?
  3. 3 In other news, MathWorks suffered a ransomware attack, losing data from over 10,000 individuals. Who knew Social Security numbers could become the main course at a cyber buffet?

+1 more story

Open briefing →

The rundown

  1. 1 Today in "The Ghostbusters Go Digital," cyber operatives nicknamed "GhostAction" are appropriating secrets from 3,325 innocent GitHub projects. Someone decided their Halloween costume this year involves digitally spooking data, proving once more that developers’ bug-ridden code isn’t the only ghost in the machine.
  2. 2 Meanwhile, in "The Botnet Chronicles," NightshadeC2 swaggers onto the scene wearing a metaphorical cape, deftly orchestrating cyber disorder with its freshly unleashed Command and Control prowess. Maybe we should start looking at botnets as the new supervillains, without the cool lairs, but just as much attitude.
  3. 3 In the plot twist of SVG-meets-Trojan, those harmless visual files harbor phishing malware, perfectly illustrating that sometimes, clipart can pack a punch akin to a digital pickpocket.

+2 more stories

Open briefing →

The rundown

  1. 1 Next, we venture into a healthcare saga that would make any hospital drama envious. Healthcare Services Group Inc. just turned 624,000 individuals into unwilling participants of a data breach thriller, complete with Social Security numbers and financial details. Wondering about their starring role on the dark web? Don't worry; identity theft services are here to save the day, one compromised account at a time.
  2. 2 Our cybercriminals today have gone global with a touch of the oriental. Chinese-speaking hackers are trying out ghost-tapping via NFC relay, scheming like masterful magicians. Despite hiccups like the Huione Guarantee going kaput, the digital phantoms continue their haunting escapades.
  3. 3 Switching gears, SafePay has burst onto the scene with more ransomware attacks than a summer blockbuster has sequels, saving all their drama for organizations that don’t speak in Cyrillic. And lastly, as if persuading unruly teenagers wasn't hard enough, researchers have found our dear GPT-4o-mini AI model is even easier to convince. Who knew AI compliance could match that of a sleep-deprived college student with a term paper due? So, grab your headphones and get ready to laugh-sigh your way through the latest in cybersecurity!
Open briefing →

The rundown

  1. 1 Meanwhile, in the chessboard world of cyber battles, Chess.com faced a data breach that exposed user details from Maine and Vermont, notably sparing any checkmate-inducing secrets. Users are now offered a tight cyber defense, which we hear pairs nicely with their next "pawn" move.
  2. 2 Corporate plot twists unfold as Workiva, the data privacy giant, experiences a breach via Salesforce, leading to some awkward watercooler conversations, someone’s definitely getting a demerit for leaving the cookie jar open!
  3. 3 And if you thought Picasso’s work was safe, think again. Cyber art thieves plan to serve stolen masterpieces to AI companies, challenging us to distinguish between a cultural renaissance or just a bug-ridden art show.

+2 more stories

Open briefing →

The rundown

  1. 1 First up, we dive into a saga involving a toy maker against the US government because apparently, robots playing hide-and-seek with kids' data is frowned upon, who knew? The FTC isn’t impressed with this data candy giveaway, and neither are we!
  2. 2 Meanwhile, over at Google, a hacker group with an award-worthy name, the Scattered LapSus Hunters, demands the firing of two security staffers without even showing a sneak peek of their alleged findings. Google has mastered the art of the "silent treatment," refusing to play along in this cyber soap opera, who’s got the popcorn?
  3. 3 Next, a housekeeping oversight at Navy Federal Credit Union led to a 378GB data leak. It's time for them to enlist 'Secure Your Servers 101' in their training because clearly, they missed that naval battle.

+3 more stories

Open briefing →

The rundown

  1. 1 First up, while you were mastering the barbecue grill this Labor Day, hackers were grilling the Internet in the planet’s largest DDoS attack, proving their work-life balance is way off. Thankfully, Cloudflare had no interest in a holiday and blocked the mayhem like a cybersecurity superhero on Red Bull.
  2. 2 Next, we turn to Jaguar Land Rover who found themselves ambushed not by paparazzi, but by cyber intruders confusing their server room for a celebrity hotspot. Somebody fetch the cat, the tech-savvy feline might just purr their systems back to health.
  3. 3 Don't fall for the latest internet hoax claiming Google wants you to change your Gmail password, because this one's faker than a sitcom laugh track. Keep calm, your inbox isn't on fire.

+2 more stories

Open briefing →

The rundown

  1. 1 Today, in a maneuver that could power an entire season of a tech spy saga, the Pentagon hit pause on a Microsoft gig employing Chinese engineers, because apparently, handing the keys to the kingdom to a possible espionage hub wasn't their brightest move. Hats off, Captain Obvious!
  2. 2 Meanwhile, over at Microsoft, there's a VS Code vulnerability allowing savvy coders to resurrect the ghost of extensions past. It's like Halloween but for VS Code, spooky!
  3. 3 ScarCruft is back at it, targeting the intellectual elite of South Korea with their notorious RokRAT malware. A plot twist when you could have just hacked anybody, right?

+3 more stories

Open briefing →

The rundown

  1. 1 Over in the realm of 5G, network slicing is the latest buzz, a virtual deli counter where everyone gets their cybersecurity slice of choice. But hackers aren’t exactly lacking appetite, finding opportunities hidden in the toppings of this tech delicacy. Plus, ransomware gangs are trading in their vintage tactics for sleeker API and SaaS disruptions, causing businesses to wonder if they remembered to save backup before dessert.
  2. 2 To top things off, AI assistants like Alexa and Siri are proving they can offer more than just weather updates by inadvertently teaming up with cybercriminals to encrypt data and wreak havoc. Join us as we break down these stories with a dash of humor, a twist of sarcasm, and just enough bite to keep your systems secure (and entertained).
Open briefing →

The rundown

  1. 1 First up, a zero-click exploit is crashing through WhatsApp's defenses, making hacking chats easier than getting your pals to join yet another book club. If confirmed, this could redefine 'unread messages' for many users, frankly, who needs them anyway?
  2. 2 Next, Google urges its 2.5 billion users to reset passwords after a Salesforce system breach by the cyber-culprits UNC6040, AKA ShinyHunters. The caper feels right out of a cyber mystery novel, where the company names and contacts are the unsung stars. Remember, folks, double-check those security settings unless you're into living on the edge!
  3. 3 Meanwhile, TamperedChef is turning your free PDF editor download into a digital disaster, pilfering your data under the guise of efficiency. Because who knew free would come at such a steep price? Investing in reputable software now feels like a bargain.

+2 more stories

Open briefing →

The rundown

  1. 1 In today’s episode, we kick off with the UK government hilariously scrambling to fix security leaks like it's trying to catch droplets in a sieve. Spoiler alert: exposing Afghan data wasn't part of their "Best Government Practices" training.
  2. 2 Next, we swing by Click Studios, where their latest dance move involves patching a sneaky vulnerability. Now, only those with an invite can join the Passwordstate fiesta, because nothing says "Welcome" like a good security patch.
  3. 3 Over in the world of cyber espionage, Amazon plays the unlikely superhero, crashing APT29's latest cyber shindig. What’s cooler than high-stakes techno-drama? A corporate giant proving that even digital villains need a raincheck now and then.

+3 more stories

Open briefing →

The rundown

  1. 1 Our headliner features a ransomware group who went full minimalist by not just stealing, but vaporizing data and backups from Azure. It's the ultimate data detox, though someone should explain that less isn't always more, especially in business continuity.
  2. 2 Meanwhile, say hello to MystRodX, the backdoor who's working overtime on both Windows and Linux. This cyber-caliber Houdini is dodging firewalls faster than office workers dodge responsibility for microwaving fish.
  3. 3 Next up, meet the Hook Banking Trojan, now doubling as a wannabe ransom artist, boasting 107 remote commands, and crash-scene invader of Android phones everywhere. It’s got more tricks than a villain at a hacker's gala, proving everyone loves a good sequel.

+2 more stories

Open briefing →

The rundown

  1. 1 The plot thickens as ShadowSilk swoops across international lines, making IT departments everywhere feel like bewildered sidekicks in their own digital heist movie. Meanwhile, the Cephalus ransomware has taken a page out of Greek mythology, infiltrating organizations through weak RDP credentials, leaving teams clutching their Achilles’ heels. Just remember, multi-factor authentication is your proverbial Herculean armor.
  2. 2 And finally, in today's irony-laden narrative, Salesloft, thanks to an overly chatty AI assistant from Drift, decided to throw a confidential data party with Salesforce customer details. Picture a digital ‘whodunnit’ where the cat’s forever out of the proverbial bag.
  3. 3 Join us daily to find out who the hackers pick as their next guest of honor in the world’s weirdest online soap opera that you never asked for.
Open briefing →

The rundown

  1. 1 Today, we've got OldGremlin making a less-than-desired encore! This Russian-speaking ransomware group has returned, ready to scam once more, you’d think they'd retire their antics by now...
  2. 2 In a surprising twist, cybercriminals have innovatively conquered the humble "Contact Us" form, launching attacks with such high praise it’s almost deserving of a sarcastic golf clap. Effortlessly sneaky hackers posing as a White House butler have charmed their way into sensitive data, who knew customer service could be so dangerous?
  3. 3 Up next, hackers pull out their UpCrypter tool, out-fishing us all with their ridiculously realistic phishing campaigns. The drama never ends, just what every cybersecurity officer dreams of.

+3 more stories

Open briefing →

The rundown

  1. 1 Kick things off with a bang as more than 19 million Android users hit the uninstall button! Google Play bid farewell to apps spreading the Anatsa banking trojan, proving once again that clicking "I agree" might cost you more than just a cup of coffee. Meanwhile, Android users worldwide breathe a collective sigh of relief like they've just given a cyber bank robber a run for their money.
  2. 2 Got a knack for saving money on digital mischief? Cybercrooks are shopping the bargain-bin VPS aisle to launch SaaS hijacking attacks. Talk about cybercrime on a budget, where cheap thrills meet costly data raids!
  3. 3 Over at Exel Composites, it's less Oscars and more heist-worthy drama as the World Leaks ransomware group claims to leak everything from aerospace blueprints to corporate secrets, while IT folks embark on an epic journey to make sense of the chaos.

+1 more story

Open briefing →

The rundown

  1. 1 Next, we dive into Data I/O's ransomware fiasco. Imagine being locked out of your own systems, it’s like being ghosted by your own smartphone. Recovery is underway, but maybe it's time they consider a retro backup method that won't crash...like punch cards.
  2. 2 Story three brings us to a Go module that's turned malicious, acting like a tuxedo-wearing raccoon stealing SSH credentials and delivering them via Telegram. Do cyber wizards have a spell for that? We sure hope so, because this raccoon looks like it’s ready to party with sensitive data!
  3. 3 Over in the RaaS (that’s Ransomware-as-a-Service for the uninitiated) world, we introduce BQTLock, now with its own glitzy PR campaign, because why shouldn't evil have a marketing strategy?

+1 more story

Open briefing →

The rundown

  1. 1 First on our agenda, we're dissecting UnitedHealth's record-breaking 'generosity' in sharing 192 million people's data. It seems the BlackCat heist has added healthcare to their shopping spree, with medical records proving to be irresistible shopping items.
  2. 2 Next, hop aboard the "Cloudy with a chance of hackers" segment as Murky Panda hackers make a cameo, posing as over-trusting vacationers at the Cloudland Water Park only to flood customers' systems with unwanted data intruders.
  3. 3 Meanwhile, macOS devotees have had their rose-tinted glasses knocked off by the Atomic macOS Stealer. Who knew Apple's "Think Different" motto now includes "Think of being hacked"?

+3 more stories

Open briefing →

The rundown

  1. 1 First up, Europol is busting the myth of a $50K Telegram job offer to take down the Qilin ransomware gang. Spoiler alert: if it sounds like a script straight out of a cyber fairytale, that's probably all it is. Next, Microsoft is playing chess with quantum hackers of the future, pledging to make its products quantum-safe by 2033. As if we weren't already sweating 2030!
  2. 2 Meanwhile, a major electronics supplier decides to take an unexpected "holiday" after ransomware flips the off switch on their operations. Little do the machines know, workplace revolts don't automatically earn them vacation days.
  3. 3 In a twist of cyber sleuthing, Colt Technology becomes the latest victim of a ransomware group realizing they can't cash in through extortion, but who knew the dark web was running a clearance sale?

+1 more story

Open briefing →

The rundown

  1. 1 Hacked dAily is here to serve you a hot pot of all the cyber soup with a side of sarcasm. Imagine your face morphing app going rogue and landing you on the no-fly list! Thank NIST for stepping in with new guidelines that aim to outwit any wannabe evil twin plots. Have you ever thought your remote development environment was your secure sanctuary? Well, Microsoft's VS Code Remote-SSH might give you a rude wake-up call by letting attackers play jazz on your local machine. Next time, don’t share your VIP hacker pass.
  2. 2 Speaking of creative crime, hackers are making breakfast a minefield with the CORNFLAKE.V3 backdoor served up via fake CAPTCHAs. Next time you're proving you're not a robot, double-check, those cyber villains might just be out-creeping the CAPTCHA.
  3. 3 In non-breakfast-related news, someone from the Scattered Spider hacking group scored a decade in the slammer thanks to some old-school SIM swapping. At $13 million in restitution, it's no wonder they won't be laughing all the way to the digital bank!

+1 more story

Open briefing →

The rundown

  1. 1 First on our virtual platter is McDonald's, not just flipping burgers but also trying to flip the script on a security breach in their staff and partner hubs. It seems like the hacker got tired of broken ice cream machines and went for a tech makeover instead.
  2. 2 Next, we’re delving into the twisted realm of DOM-based extension clickjacking, a vulnerability even the digital Fort Knoxes, our ever-so-trusty password managers, can't outrun. If extensions were this unpredictable, maybe they're taking lessons from teenage mood swings.
  3. 3 Moving on, an Australian telecom company redefines "limited" in data breaches by exposing 280,000 customer details. Their idea of "limited" is as expansive as a thanksgiving dinner with everything but the turkey.

+2 more stories

Open briefing →

The rundown

  1. 1 ShinyHunters are at it again, as if we didn't see this coming. They infiltrated Workday via Salesforce with social engineering, proving even cybersecurity stalwarts can be led astray by small-talk. It's a digital Wild West out there, folks, where even con artists have upgraded from grandma to grandiose corporate stints.
  2. 2 Meanwhile, Google's Privacy Sandbox faces a privacy hiccup with client-side deanonymization taking the limelight. Google assures us nothing’s inherently wrong, but it’s hard not to picture Neo shaking his head as privacy's secrets escape unceremoniously under a welcome mat.
  3. 3 In other news, Singapore's "Dire Wolf" ransomware is on the prowl, stalking tech and manufacturing sectors like a tax auditor in April, while AI-powered scams charm the unassuming on social media. So, hold onto your wallets and sanity as we navigate this cyber circus together.
Open briefing →

The rundown

  1. 1 Welcome to another laugh-out-loud episode of Hacked dAily, your go-to cybersecurity podcast brought to you by Cytadel Cyber. Join us as we navigate the tangled web of today's top cyber mishaps, with a side of wit and a hint of sarcasm.
  2. 2 First up, grab your popcorn for the show of unity between hackers and IT admins who seem to think leaving 800+ N-able servers unpatched is sheer brilliance. Spoiler: the plot is full of holes, and hackers are cozying up like uninvited guests.
  3. 3 Next, the "Blue Locker" ransomware pirates have turned their sights to the oil and gas industry in Pakistan. Clearly, they believe there's Bitcoin where there's black gold, but someone should alert them, even pirates can't pay for treasure in spilled barrels of crude.

+4 more stories

Open briefing →

The rundown

  1. 1 First up, watch as the cyber theater rolls out a jaw-dropping claim: 15.8 million plain-text PayPal credentials on sale. Perhaps these hackers thought they were running a fish market, but we'll see if this blockbuster is a phishing scheme or just the latest in "Hackers Gone Wild".
  2. 2 Next, DaVita's finding themselves center stage in the hot seat, thanks to a ransomware attack, leaking nearly a million patients' data. Patients are now left with paranoia on the side, while DaVita’s not spilling the beans on invitees, they were clearly not expecting royal company.
  3. 3 And just when businesses were getting comfy with FIDO authentication, cyber tricksters have thrown a wicked wrench: sinister downgrade attacks. This is your reminder that the internet always has a Lego piece lying in wait, step cautiously!

+2 more stories

Open briefing →
Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.