Skip to content
Hacked dAily
All Episodes

Hacked dAily Episodes

Every episode of Hacked dAily: 558 daily cybersecurity briefings and counting. Breaking news on breaches, ransomware and AI threats. Page 2 of 24.

The rundown

  1. 1 Attackers are exploiting StyleSmuggler, an unpatched zero-day in Magento Open Source and Adobe Commerce, to execute code and install persistent backdoors on online stores. Merchants face risks including session theft, silent reinfection, and compromise of connected systems while no official fix is available.
  2. 2 JetBrains confirmed that attackers used a critical TeamCity flaw to access its Cadence cloud service and extract a backup containing AWS credentials, configurations, logs, and personal data. Current and former users should rotate credentials, investigate connected systems, and treat stored data and execution results as potentially compromised.
  3. 3 OpenAI has committed $1 billion in subsidised AI cybersecurity tools, training, and support for critical infrastructure and other under-resourced defenders. The initiative prioritises sectors such as water, energy, local government, banking, and open-source software, where limited security capacity increases exposure to accelerating AI-enabled attacks.

+2 more stories

Open briefing →

The rundown

  1. 1 Manchester Airports Group attackers have reportedly leaked data affecting 8.8 million people, potentially exposing passengers and others to identity theft and fraud. The disclosure highlights how ransomware groups combine data theft and public leaks to increase pressure, regulatory risk, and business disruption.
  2. 2 Insurers are examining how to cover losses linked to rogue AI, including errors, data exposure, and unauthorised actions. The uncertainty reveals a widening gap between rapid AI adoption, cyber-policy wording, and the ability to price emerging risk.
  3. 3 Attackers are targeting a critical Citrix NetScaler authentication-bypass flaw, CVE-2026-19490, following publication of a credible exploit. Active attempts have been reported across multiple countries, making urgent patching essential for organisations relying on exposed VPN and proxy gateways.

+2 more stories

Open briefing →

The rundown

  1. 1 Thomson Reuters reported unauthorized access to its C-Track court software, potentially exposing sensitive records from courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario. The incident highlights the risks of vendor cloud and backup environments, prompting password resets, access restrictions, investigations, and credit-monitoring measures.
  2. 2 China-linked hackers reportedly used USB devices to backdoor executives’ laptops, exploiting security fixes that organizations had not yet deployed. The campaign shows how basic physical access and delayed patching can bypass mature defenses and compromise high-value business environments.
  3. 3 Serbian student protesters and civil society figures were targeted with Pegasus and NoviSpy spyware, including a zero-click iPhone infection. The documented activity raises serious concerns about surveillance of political dissent, privacy, due process, and election-related interference.

+2 more stories

Open briefing →

The rundown

  1. 1 OpenAI says its Astra model has reached its highest Critical cybersecurity risk rating after autonomously finding zero-day flaws and building exploit chains across hardened systems. The results prompted a pause in training and stronger safeguards, highlighting how AI could accelerate offensive operations and shorten defenders’ response windows.
  2. 2 The UK is moving to strengthen its Cyber Security and Resilience Bill, giving ministers powers to block high-risk technology suppliers from critical infrastructure. Following an attack that disrupted a small energy facility for four days, the amendments signal greater accountability for third-party and supply-chain risk across essential services.
  3. 3 Unit 42 investigated a ransomware intrusion where frontier AI agents helped an attacker breach an enterprise network in under 10 hours. The case shows how AI can automate reconnaissance, credential theft and cloud compromise, increasing pressure on organisations to secure AI, DevOps and identity systems and automate containment.

+2 more stories

Open briefing →

The rundown

  1. 1 The FBI is investigating a dark web service offering scans of more than 153 million U.S. and Canadian driver’s licenses and other identity documents, potentially stolen from a Louisiana identity verification provider. The breach highlights how centralized ID databases can create large-scale risks of fraud, stalking, and identity abuse.
  2. 2 SonicWall says attackers are exploiting two zero-day vulnerabilities in SMA1000 secure remote access appliances, potentially enabling unauthenticated remote code execution. Customers using the 6210, 7210, or 8200v should apply hotfixes urgently, as the devices are high-value targets and attack details remain limited.
  3. 3 Attackers are actively exploiting a critical unauthenticated remote code execution flaw in Langflow to steal environment variables, AWS secrets, and OpenAI API keys. With hundreds of attempts observed, exposed instances running version 1.4.2 or earlier present a direct risk to AI workflows, cloud infrastructure, and sensitive data.

+2 more stories

Open briefing →

The rundown

  1. 1 Fire Ant, a Chinese espionage group, is reportedly moving from VMware environments to Cisco routers, TACACS servers, and Linux management hosts. By turning trusted infrastructure into covert surveillance platforms, the campaign highlights the need to protect network devices and preserve log integrity.
  2. 2 North Korean operatives are expanding remote job fraud beyond IT into healthcare, sales, marketing, and finance. With stolen identities, proxy workers, laptop farms, and AI-assisted interviews, the campaign creates significant insider-threat, compliance, sanctions, and hiring risks for employers.
  3. 3 French intellectual property firm Questel was targeted by ShinyHunters, which allegedly published data including around 1.2 million unique email addresses and associated contact details. The exposure could enable phishing, fraud, and targeted attacks against employees, customers, and partner organizations.

+2 more stories

Open briefing →

The rundown

  1. 1 PaperCut print servers are being actively probed after researchers confirmed a pre-authentication remote code execution flaw in real environments. With roughly 47% of tracked systems still unpatched, and older versions lacking a fix, schools, hospitals, and enterprises should restrict exposure, patch where possible, and investigate for compromise.
  2. 2 Malicious Chrome and Edge extensions stole cryptocurrency, credentials, browser data, and history, while delivering phishing and fake-update lures. Nineteen extensible modules affected tens of thousands of users, highlighting the risks of trusted software updates and the need to reset credentials and move crypto assets to fresh wallets.
  3. 3 U.S. officials revised claims that agencies including the Senate, Federal Reserve, and NASA were breached by Chinese spies, clarifying they were targets of the QTFY platform rather than confirmed victims. The change highlights the business and national-security consequences of overstating cyber incidents before evidence is verified.

+2 more stories

Open briefing →

The rundown

  1. 1 A suspected Chinese-speaking operator breached a Philippine nuclear research body and a marine engineering company linked to the Navy by exploiting unpatched ownCloud and WordPress systems. Stolen nuclear, personnel, financial, and credential data, and exposed attacker tools, highlight the risks facing government and defence-connected organisations.
  2. 2 Hasbro says a network incident exposed personal and financial information belonging to employees and former employees, including 436 Massachusetts residents. The incident reportedly followed a cyberattack that caused $11 million in recovery costs and delayed $25 million in sales, demonstrating the operational and financial consequences of a breach.
  3. 3 Five critical vulnerabilities were found in popular WordPress plugins and themes, including flaws enabling authentication bypass, privilege escalation, and remote code execution. Attackers could take over websites, reset accounts, or run malicious code, reinforcing the need for rapid patching and disciplined third-party software governance.

+2 more stories

Open briefing →

The rundown

  1. 1 McKesson disclosed unauthorized access to third-party applications and possible data exfiltration after ShinyHunters claimed to have stolen 284 million patient records. The incident highlights how compromised identities and social engineering can expose healthcare data and disrupt critical services.
  2. 2 President Trump signed an executive order restricting foreign-made power-grid equipment, software, remote access and maintenance services considered supply-chain or national-security risks. The policy brings cybersecurity further into procurement decisions as energy demand grows across AI, data centers, manufacturing and defense.
  3. 3 Berlin says hackers stole data from its administrative network and are attempting extortion, while investigators examine further exfiltration. Manchester Airports Group also reported customer-data theft from booking and WiFi systems at three airports, showing how attacks can expose personal information and disrupt public services without compromising core operations.

+2 more stories

Open briefing →

The rundown

  1. 1 Manchester Airports Group says hackers stole customer data linked to Wi-Fi sign-ups, parking, lounge and Fast Track bookings at three UK airports. Email addresses, phone numbers, vehicle registrations and postcodes were exposed, creating phishing and privacy risks, although payment details and airport operations were unaffected.
  2. 2 Australian authorities arrested two men allegedly linked to TeamPCP, a cybercrime group accused of abusing open-source software to attack organizations worldwide. The arrests may disrupt a threat tied to credential theft, cloud compromise and software supply-chain attacks, while highlighting persistent weaknesses in developer ecosystems.
  3. 3 Researchers found backdoors in routers from Chinese manufacturers that could bypass authentication and enable unauthorized access. The discovery raises espionage, credential-theft and remote-compromise concerns for businesses and consumers, reinforcing the need for stronger hardware supply-chain oversight.

+2 more stories

Open briefing →

The rundown

  1. 1 U.S. authorities disrupted QTFY, a Chinese state-sponsored espionage operation that allegedly targeted critical infrastructure, federal agencies, Congress, and an election system since 2018. The takedown cut off infrastructure used for reconnaissance and intrusion, but the campaign highlights the persistent risk to government and private-sector networks.
  2. 2 Boston Scientific disclosed a global cyberattack that disrupted IT systems, business applications, and customer order processing. The incident shows how attacks on healthcare suppliers can affect international operations and create wider supply-chain and patient-care risks.
  3. 3 The ATF is investigating a cybersecurity incident affecting a standalone system, which the Justice Department classified as a major incident. The agency contained the issue and reported no broader impact, while an unverified Qilin ransomware claim underscores the challenges of rapid attribution and response.

+2 more stories

Open briefing →

The rundown

  1. 1 Carhartt’s reported breach count fell from nearly 25 million to about 12.9 million after synthetic benchmark data, duplicates, and inactive addresses were removed from a Databricks analytics warehouse. The incident shows how unverified figures can mislead executives, distort public reporting, and overstate business and customer impact.
  2. 2 A major DDoS attack has disrupted Norway’s shared government digital infrastructure, affecting login, e-signature, secure mail, and data exchange services. Although there is no evidence of a breach or data loss, the repeated attacks expose the operational fragility of critical public services and have triggered notifications to security and privacy authorities.
  3. 3 The Dutch Data Protection Authority fined Uber €825 million over automated driver suspensions made without meaningful human review or clear disclosure. Uber is appealing, but the case signals that AI-driven decisions affecting livelihoods require transparency, accountability, and human oversight.

+2 more stories

Open briefing →

The rundown

  1. 1 ReliaQuest repelled a phishing and social-engineering campaign in which attackers impersonated an employee, captured credentials, and obtained an MFA approval. Strong device-trust controls limited access to a view-only dashboard, demonstrating how layered defenses can contain identity attacks before they reach systems or customer data.
  2. 2 The U.S. Department of Justice reached a $400 million settlement with TikTok, ByteDance, and affiliates over alleged violations of children’s privacy laws. Although the agreement includes no finding of liability, it highlights mounting regulatory, compliance, and reputational risks for platforms handling children’s data.
  3. 3 Philippine maritime and marina agencies are investigating a ransomware attack that disrupted government operations. The incident underscores the exposure of transport and regulatory services, while questions remain about affected systems, data theft, and recovery costs.

+2 more stories

Open briefing →

The rundown

  1. 1 UK authorities attributed an attack that took a small British power generator offline for four days to Iran-linked hackers, while confirming there was no wider energy-system impact. The incident highlights growing state-backed pressure on critical infrastructure and the need for stronger resilience across essential services.
  2. 2 New analysis warns that emerging industrial communication protocols could expand the attack surface faster than security controls can mature. For factories, utilities, and other operators, inadequate protection could increase the risk of disruption, unauthorized access, safety incidents, and costly downtime.
  3. 3 Mid-market companies represented 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026. Manufacturing was hit hardest, reinforcing how limited security resources, patching gaps, and stolen credentials can expose both individual firms and wider supply chains.

+2 more stories

Open briefing →

The rundown

  1. 1 ToxicPanda 2.0 has expanded from a small European campaign to 349 financial institutions across 16 countries. By abusing trusted Android functions, the malware can steal banking credentials and device PINs, highlighting growing mobile fraud risks and the need for stronger endpoint defenses.
  2. 2 A critical flaw in NASA/JPL’s AIT-GUI spacecraft command software allowed unauthenticated users or malicious websites to send commands, run scripts, and control connected systems. Rated 9.4, the vulnerability shows how basic web weaknesses can become serious operational and hardware-control risks; version 2.5.2 fixes the issue.
  3. 3 An alleged Telegram data leak exposed 569,000 Golf Canada email addresses, along with names, usernames, birth dates, genders, and approximate locations. The data could enable phishing, fraud, and highly targeted social engineering, while the source of the exposure remains unconfirmed.

+2 more stories

Open briefing →

The rundown

  1. 1 Microsoft says a maximum-severity Entra ID flaw is being actively exploited, potentially allowing attackers to bypass security boundaries and gain elevated access. Because Entra ID governs authentication across many cloud environments, compromise could undermine enterprise-wide security and persistence controls.
  2. 2 Apollo Global Management reports that social-engineering attackers accessed cloud platforms and exposed personal data, including Social Security numbers, during a wider campaign targeting financial firms. The incident highlights how voice phishing and extortion can create serious regulatory, reputational and customer-risk consequences.
  3. 3 Researchers found more than 9,300 exposed AWS access keys remain active, including root and administrator credentials capable of granting full account control. Poor rotation and limited monitoring leave organizations vulnerable to data theft, service disruption, unauthorized privileges and costly cloud abuse.

+2 more stories

Open briefing →

The rundown

  1. 1 Critical infrastructure threat: U.S. agencies warn that attackers are using AI-generated scripts to target Siemens S7 controllers across water, food, energy, chemical, manufacturing and commercial facilities. The activity could disrupt operations, cause safety incidents and expose data, while AI lowers the barrier to attacking industrial systems.
  2. 2 CareCloud breach: CareCloud says unauthorized access to an AWS environment affected 3,756,469 people and caused an eight-hour outage. Patient data may have been exposed, creating privacy, phishing and regulatory risks; identity protection is being offered to notified individuals.
  3. 3 CameraSwarm: Researchers say more than 14,500 Dahua IP cameras were compromised in a 35-day campaign, mainly in Ukraine and Russia. The attacks enabled surveillance, credential theft and persistent access, underscoring the business risk of unsecured, outdated devices.

+2 more stories

Open briefing →

The rundown

  1. 1 CISA and the FBI report that Medusa ransomware has identified more than 500 victims, including over 200 added in the past year, with healthcare and critical infrastructure heavily targeted. Its rapid exploitation of vulnerabilities, stolen credentials, and legitimate remote-access tools increases the risk of sudden outages, data theft, and extortion.
  2. 2 U.S. prosecutors have indicted 17 Iranians allegedly linked to the Mabna Institute, accusing them of stealing 31.5 terabytes of research from more than 100,000 academic accounts and at least 144 universities. The case highlights the scale and long-term economic impact of state-sponsored intellectual-property theft.
  3. 3 Ransom Busters claims to have breached HTML and accessed internal systems and sensitive data. If confirmed, the incident could create exposure, operational disruption, extortion risk, and urgent obligations for the company and its stakeholders.

+2 more stories

Open briefing →

The rundown

  1. 1 A hacker claims to have stolen 36 million Microsoft Azure account records from major companies, allegedly by exploiting exposed cloud assets. The data has not been independently verified, but if confirmed, the incident would highlight how cloud misconfigurations can enable widespread credential compromise.
  2. 2 Cybercrime group BlackFile, also tracked by Google as UNC6671, remains active against financial firms and other enterprises through voice phishing and social engineering. Its multi-brand extortion model and million-dollar demands show that human-focused attacks continue to create serious financial and reputational risk.
  3. 3 A suspected Gentlemen ransomware affiliate reportedly used Claude Code during intrusions against at least eight organizations, including an energy utility, financial firm, and manufacturers. The case demonstrates how generative AI can accelerate credential theft, network access, data exfiltration, and ransomware operations, while also introducing risks of accidental disruption.

+2 more stories

Open briefing →

The rundown

  1. 1 Researchers linked the PATCHCORD espionage campaign to suspected APT36 activity after it targeted Afghan telecom providers and South Asian critical infrastructure with fake VPN installers and telecom tools. Its stealthy persistence and use of trusted cloud services raise significant risks for government and infrastructure networks.
  2. 2 Secure messaging provider Threema suffered multiple large-scale DDoS attacks, causing severe disruption across several countries and affecting its colocation partner. The incident highlights the operational and availability risks facing privacy-focused communication services.
  3. 3 SafePal reported that a flaw in its order-tracking system exposed data belonging to nearly 40,000 customers, including contact, shipping, and purchase details. Although wallets and financial credentials were not affected, the information could support targeted phishing and social engineering, with the data reportedly offered for sale.

+2 more stories

Open briefing →

The rundown

  1. 1 Attackers are exploiting CVE-2026-58231, a maximum-severity SAP Commerce Cloud flaw, just days after its patch was released. The unauthenticated vulnerability could enable code execution and internal compromise, making immediate patching and exposure reviews essential.
  2. 2 ShinyHunters claims it stole 623GB from RingCentral after a social engineering attack and leaked data affecting roughly 1.6 million accounts. The incident highlights identity risks targeting cloud providers and the customers that depend on them.
  3. 3 An Akira ransomware affiliate reportedly disrupted its own operation while attempting to evade endpoint detection. The failure reinforces the value of layered defenses, EDR, and rapid response in preventing encryption and data theft.

+2 more stories

Open briefing →

The rundown

  1. 1 France’s tax authority confirmed a June breach in which stolen or misused credentials enabled access to personal and business data. The scale remains unclear, but the incident highlights the exposure of sensitive government information and the consequences of weak identity controls.
  2. 2 Researchers say the LiteLLM supply chain incident exposed more than 2,500 organizations through an earlier compromise of Aqua Security’s Trivy scanner. Attackers stole credentials, tokens, and API keys from development environments, showing how trusted tools can create persistent and far-reaching third-party risk.
  3. 3 Apple issued threat notifications in 110 countries to people potentially targeted by mercenary spyware, including journalists, politicians, diplomats, and lawyers. Recipients should treat the alerts seriously, as targeted surveillance can create major personal, reputational, and organizational security risks.

+2 more stories

Open briefing →

The rundown

  1. 1 U.S. expands private offensive cyber operations: The White House has directed the National Coordination Center to create a program allowing vetted security firms to conduct limited, government-approved operations against foreign cybercrime groups. Strict oversight, financial guarantees, and defined targets aim to reduce ransomware and fraud, but the initiative raises significant legal, operational, and escalation risks.
  2. 2 Clop claims attacks on Shell and Philips: Both companies confirmed security incidents while investigating the scope, as Clop alleged it stole large volumes of data. The claims remain unverified, but the case highlights how data theft can drive extortion, regulatory exposure, and business disruption.
  3. 3 VMware vCenter flaw under active attack: A critical vulnerability is being exploited against enterprise virtualization environments, where unauthorized access could enable broader network compromise. Because vCenter controls much of the virtual infrastructure, delayed patching and weak segmentation could allow one flaw to escalate into a full environment takeover.

+2 more stories

Open briefing →
Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.