Skip to content
Hacked dAily
All Episodes

Hacked dAily Episodes

Every episode of Hacked dAily: 500 daily cybersecurity briefings and counting. Breaking news on breaches, ransomware and AI threats. Page 2 of 21.

The rundown

  1. 1 A Cursor AI agent has wiped PocketOS's primary database and backups in just nine seconds, spotlighting the critical need for robust AI management and oversight in safeguarding essential infrastructure.
  2. 2 GoDaddy faces allegations of mismanaged domain transfer without standard security checks, posing questions about their security protocols and risking client trust in their handling of digital assets.
  3. 3 A hacker claims the theft of 300,000 user records from Polymarket, yet the platform denies any breach. This incident underscores the ongoing cybersecurity challenges in protecting sensitive data in digital markets.

+3 more stories

Open briefing →

The rundown

  1. 1 Vimeo suffered a data breach through Anodot, exposing user data including email addresses and hashed passwords. This incident stresses the importance of secure third-party data management to prevent unauthorized access and protect user information.
  2. 2 A critical vulnerability exists in Hugging Face's LeRobot platform, susceptible to remote code execution. This poses risks of data compromise and underscores the need for swift mitigations and improved AI infrastructure security.
  3. 3 Lloyds Bank compensates 1,625 customers following a data breach, highlighting financial sector challenges in data protection. The breach raises concerns about the trust and security measures crucial to safeguarding sensitive customer information.

+3 more stories

Open briefing →

The rundown

  1. 1 Microsoft reports an outage affecting Outlook.com users, resulting in widespread access issues with no estimated resolution time. This incident highlights the necessity for reliable email services as disruptions can severely impact communication and operations.
  2. 2 Chinese national Song Wu orchestrated a spear-phishing campaign targeting NASA and the U.S. military to illicitly obtain sensitive software, posing critical national security risks. His evasion emphasizes ongoing cybersecurity challenges against espionage efforts.
  3. 3 Experts reveal the Vidar infostealer spreading via fake CAPTCHA pages, utilizing JPEG and TXT files to bypass detections. This trend showcases the increasing sophistication of threat actors and the vital need for enhanced cybersecurity strategies.

+2 more stories

Open briefing →

The rundown

  1. 1 First, Udemy faces a data breach affecting over 1.4 million accounts, exposing personal information. This highlights the urgent need for educational platforms to bolster security and protect user data, maintaining trust in digital education.
  2. 2 Next, a critical vulnerability uncovered in CrowdStrike LogScale could grant unauthorized file access. This flaw emphasizes the necessity for organizations to swiftly apply patches to safeguard data integrity within cybersecurity tools.
  3. 3 In a significant incident, American utility giant Itron reported a breach of their IT network. This breach accentuates the essential role of robust cybersecurity in protecting infrastructure operations from disruptions.

+3 more stories

Open briefing →

The rundown

  1. 1 Top Story 1: A crime group is exploiting Microsoft Teams to impersonate IT help desks, using phishing links and malware to compromise corporate data. This underscores the urgent need for better employee cybersecurity training and robust defenses against phishing threats.
  2. 2 Top Story 2: A breach on the npm platform via Bitwarden's compromised CLI spreads the TeamPCP campaign, stressing the importance of software supply chain security and the verification of package integrity to protect sensitive data.
  3. 3 Top Story 3: A data breach at ADT, instigated by ShinyHunters, exposes customer information and threatens the company's reputation. This highlights the necessity for strong cybersecurity measures and rapid incident response plans to defend against advanced threats.

+2 more stories

Open briefing →

The rundown

  1. 1 A sophisticated phishing campaign targeting Germany’s Bundestag President leverages compromised Signal accounts, highlighting increased risks for political figures and stressing the need for stronger security in government communications.
  2. 2 Cybersecurity researchers are embedding Bluetooth trackers in mail to unveil supply chain vulnerabilities. This innovative tactic reveals risks in global parcel flows, underscoring the criticality of enhancing security across logistics operations.
  3. 3 The BlackFile cyber extortion group is escalating vishing attacks on businesses, using social engineering to extract sensitive data. This surge calls for immediate enhancements in organizational security training and awareness.

+3 more stories

Open briefing →

The rundown

  1. 1 Top Story 1: A breach at Rail Europe has exposed Interrail travelers' data on the dark web, urging passport cancellations for affected individuals. This highlights urgent cybersecurity needs in travel, where data protection is crucial for maintaining customer trust.
  2. 2 Top Story 2: Carnival Corporation's cyber incident has compromised over 7 million accounts, exposing sensitive information and spotlighting the pressing need for fortified data security in the digitizing travel sector.
  3. 3 Top Story 3: Rituals has experienced a data breach within its My Rituals membership, exposing names and addresses but no financial data. The incident renews focus on phishing risks and the importance of swift cybersecurity response and cooperation with authorities.

+2 more stories

Open briefing →

The rundown

  1. 1 YouTube will provide Hollywood studios with deepfake detection technology to combat manipulated content, preserving creative authenticity and trust in media.
  2. 2 The New South Wales Government faces a cyber incident involving a Treasury data breach. The situation emphasizes the need for robust measures to protect government data and public trust.
  3. 3 Researchers have identified a new threat, the "DinDoor Backdoor," exploiting the Deno runtime environment, supported by 20 C2 servers. This highlights the need for strengthened defenses against complex backdoor vulnerabilities.

+3 more stories

Open briefing →

The rundown

  1. 1 Today, Google has patched a critical flaw in the Antigravity IDE that allowed for prompt injection and potential code execution. This swift action helps preserve the secure development landscape, underlining the need for continuous software security vigilance.
  2. 2 In the UK, an investigation targets Telegram and various teen chat sites for possibly enabling CSAM sharing. This move spotlights the urgent global demand for tech accountability and enhanced digital safety for vulnerable users.
  3. 3 The Lotus Wiper malware poses a grave threat to the energy and utilities sector, capable of irreversibly deleting data. Its emergence calls for fortified cybersecurity protocols to protect critical infrastructure and national security.

+3 more stories

Open briefing →

The rundown

  1. 1 Vibe coding company Lovable denies data leakage, blaming 'intentional behavior' by a third party. Their dispute with HackerOne highlights the complexities of vulnerability management and the reputational risks of ambiguous incident responses.
  2. 2 Bluesky, a decentralized social media platform, suffered a DDoS attack disrupting user access. This incident raises concerns about the resilience of decentralized platforms and underscores the need for robust defensive strategies in the evolving digital landscape.
  3. 3 Zoom introduces new verification features targeting AI-driven impersonation, enhancing meeting security against deepfake threats. This development points to the increasing necessity for robust digital identity safeguards in business communications.

+2 more stories

Open briefing →

The rundown

  1. 1 Cybercriminals are exploiting Apple account change notifications to send phishing emails, tricking users into revealing sensitive data. This highlights the ongoing sophistication of phishing tactics and the need for stronger security protocols.
  2. 2 Vercel has suffered a data breach, with hackers accessing and selling sensitive information online. This incident underscores the critical need for robust data protection as businesses face increasing cybersecurity threats.
  3. 3 A British hacker has admitted to stealing $8 million in virtual currency by breaching company networks. This case stresses the importance of fortifying security defenses against sophisticated cybercriminal tactics to prevent financial and reputational damage.

+2 more stories

Open briefing →

The rundown

  1. 1 A recent incident exposes the limitations of simply changing email passwords against sophisticated attacks, like phishing, stressing the need for multi-factor authentication to protect sensitive information.
  2. 2 Researchers exploit vulnerabilities in AI models, including ChatGPT, to manipulate memory and influence responses, spotlighting an urgent need for stronger AI safeguards to protect critical data.
  3. 3 The discovery of "MAD" malware, capable of infiltrating systems through basic text commands, underscores the evolution of cyber threats and the crucial need for stringent organizational security protocols.

+2 more stories

Open briefing →

The rundown

  1. 1 A recent phishing attack disguised as a DHL email targeted a German industrial supplier, using SimpleHelp to gain remote access. This incident emphasizes the growing sophistication of phishing tactics exploiting trusted brands for malicious purposes.
  2. 2 In London, a ransomware attack from two years ago continues to impact healthcare services, revealing vulnerabilities in critical infrastructure and pressing the need for robust defenses to protect patient safety.
  3. 3 A cargo theft criminal group exploits stolen credentials to infiltrate logistics firms, manipulating shipping details and evading detection. This highlights the urgent necessity for enhanced cybersecurity within the supply chain industry to prevent significant losses.

+3 more stories

Open briefing →

The rundown

  1. 1 A fake Slack download disguises a harmful trojan granting attackers an invisible desktop, threatening corporate networks reliant on Slack for communication. The deceptive URL technique enables unauthorized access to sensitive data, risking severe business implications.
  2. 2 The EU's Digital Age Verification App is hacked in less than two minutes, raising alarms over its design flaws. Its compromise poses a critical threat to the broader European Digital Identity Wallet ecosystem, urging urgent action from the European Commission.
  3. 3 Matthew Lane receives a federal prison sentence for the PowerSchool breach affecting 70 million individuals. This substantial breach highlights the growing involvement of young hackers, prompting a call for stronger data security measures and youth intervention strategies.

+3 more stories

Open briefing →

The rundown

  1. 1 Microsoft has issued patches for a critical SharePoint zero-day vulnerability and 168 other vulnerabilities. Active exploitation underscores the crucial need for rigorous patch management to protect systems and sensitive data.
  2. 2 President Trump pushes for the extension of Section 702 of the Foreign Intelligence Surveillance Act, sparking debate over balancing national security with privacy rights. This decision carries implications for intelligence operations and privacy policies.
  3. 3 A phishing campaign tricks YouTube creators with fake copyright strike notices, jeopardizing their Google credentials. The attack illustrates how compromised accounts can lead to reputational damage and loss of income for content creators.

+3 more stories

Open briefing →

The rundown

  1. 1 Today, we delve into a recent exploit on Booking.com, where cybercriminals leveraged social engineering to extract user credentials, underscoring the critical need for better user education in combating phishing techniques.
  2. 2 Next, we explore Omnistealer, a new infostealer utilizing blockchains like TRON and Binance Smart Chain for resilient malware hosting, complicating takedown efforts and compromising over 300,000 credentials across sectors.
  3. 3 In legal developments, Florida Attorney General James Uthmeier is probing OpenAI over potential ChatGPT involvement in a university shooting, spotlighting broader issues of AI tools influencing harmful behaviors and OpenAI's ongoing safety enhancements.

+3 more stories

Open briefing →

The rundown

  1. 1 Our Top Story: European fitness chain Basic-Fit has faced a data breach impacting the personal information of one million members. This highlights vulnerabilities within non-traditional targets and emphasizes the need for strong cybersecurity protocols to protect customer data.
  2. 2 In Latin America, the JanelaRAT malware has surged, with Brazil seeing 14,739 attacks targeting banks. This campaign threatens financial data, stressing the urgency for improved cybersecurity in emerging markets.
  3. 3 A new discovery reveals a 0-day vulnerability that can disable CrowdStrike's EDR solution, posing significant threats to endpoint security. This incident raises questions about the robustness of trusted EDR tools and the need for enhanced protection measures.

+2 more stories

Open briefing →

The rundown

  1. 1 China is integrating AI to reform education by preparing lessons and grading, aiming to streamline learning and reduce teachers' workloads. This could redefine global educational practices and demonstrates China's commitment to tech-driven innovation.
  2. 2 Ransomware groups now utilize 'EDR killers' to disable Endpoint Detection and Response systems, bypassing advanced security measures. This highlights the need for firms to strengthen cybersecurity defenses to prevent potential breaches and financial losses.
  3. 3 A joint operation by FBI Atlanta and Indonesian Police dismantled the W3LLSTORE phishing marketplace, disrupting a major hub for cybercriminals. The takedown showcases international efforts against cybercrime and the importance of solid defense strategies for business protection.

+3 more stories

Open briefing →

The rundown

  1. 1 Today, we explore the breach of a Chinese supercomputer, where a hacker has exfiltrated 10 petabytes of sensitive defense-related data. This highlights vulnerabilities in China's infrastructure and raises significant global security and diplomatic concerns.
  2. 2 In Hungary, a notable cyber blunder saw government systems compromised due to the weak password "FrankLampard." This incident stresses the urgent need for stringent password policies to safeguard critical data.
  3. 3 The FBI's retrieval of deleted Signal messages via iPhone settings unveils a potential privacy vulnerability in encrypted communications. This discovery calls for heightened awareness of device configurations to ensure messaging confidentiality.

+3 more stories

Open briefing →

The rundown

  1. 1 Fake Anthropic Website: An impersonating site spreading PlugX malware has targeted users of Anthropic's Claude. The spoofed site deceives users into running a trojanized installer, emphasizing the paramount importance of safe download practices.
  2. 2 VENOM Phishing Campaign: Sophisticated phishing tactics target senior executives to steal Microsoft credentials. This exposure risks unauthorized access to high-level corporate data, stressing the urgency for enhanced security measures.
  3. 3 Sockpuppeting Jailbreak: A single-line exploit circumvents security in 11 major AI models, affecting ChatGPT and others. OpenAI and AWS Bedrock have responded with blocks, highlighting the need for consistent vulnerability management.

+2 more stories

Open briefing →

The rundown

  1. 1 Meta's data protection challenges intensify as a former employee allegedly accessed 30,000 private Facebook images, surfacing persistent insider threats and questioning existing cybersecurity frameworks.
  2. 2 A data breach at MyLovely.AI has exposed 106,000 users' sensitive information to the dark web, escalating concerns over privacy in rapidly growing AI applications and exposing users to potential doxxing and sextortion.
  3. 3 A cyber attack on Zephyr Energy rerouted £700,000 meant for a contractor, spotlighting vulnerabilities in business communication systems and the pressing need for stringent security measures.

+2 more stories

Open briefing →

The rundown

  1. 1 Anthropic unveils Claude Mythos, a revolutionary AI model under Project Glasswing aiming to preemptively secure software from cyber threats. This collaboration with major security players elevates software defenses but brings potential misuse concerns.
  2. 2 AMAInterview.ai suffers a data breach, exposing over 24,000 user records to cybercriminals. This incident stresses the urgent need for robust data security practices in digital platforms managing sensitive personal information.
  3. 3 Google introduces API keys for its Gemini service on Android, enhancing connectivity and user convenience. This move aligns with Google's strategic integration of AI, promising seamless user experiences and streamlined tech operations.

+2 more stories

Open briefing →

The rundown

  1. 1 T-Mobile has confirmed a data breach exposing customer information, including names, addresses, and phone numbers, but reported no sensitive data was compromised. This highlights the persistent vulnerabilities in telecommunications and underscores the need for enhanced cybersecurity measures.
  2. 2 A major outage on April 3 paralyzed Russian banking apps, affecting institutions like Sberbank and Alfa-Bank, due in part to new VPN restrictions. As businesses faced disruptions, the event underscores Russia’s effort to strengthen internet control, impacting online freedoms.
  3. 3 The Space Bears ransomware group attacked Brooklands of Mornington, threatening to leak sensitive employee and guest data if extortion demands aren't met. This breach emphasizes increased ransomware threats to the hospitality sector, stressing the need for stringent cybersecurity defenses.

+2 more stories

Open briefing →
Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.