Skip to content
Hacked dAily
All Episodes

Hacked dAily Episodes

Every episode of Hacked dAily: 500 daily cybersecurity briefings and counting. Breaking news on breaches, ransomware and AI threats. Page 21 of 21.

The rundown

  1. 1 First up, Meta's Llama framework finds itself with an open door for remote code execution risks. It's like inviting AI systems to an all-you-can-hack buffet. Meta, maybe it's time to hire a virtual bouncer?
  2. 2 Next, the cyber curveball: The mischievous MintsLoader group is rolling out StealC malware and BOINC, as smoothly as a pizza delivery guy interrupting your binge-watch session. Grab your popcorn; this cyber heist promises a ton of suspense!
  3. 3 Meanwhile, Cobalt Strike and SOCKS proxies are channeling their inner Bonnie and Clyde as they usher in LockBit ransomware, with less-than-stellar customer service skills. These bad guys are the modern equivalent of an IT department gone rogue, showcasing their misplaced talents.

+2 more stories

Open briefing →

The rundown

  1. 1 In today's top stories: Subaru swiftly addresses a security vulnerability in their Starlink connected vehicle service, which posed risks of remote hacking and exposure of sensitive data for cars across the U.S., Canada, and Japan. Quick action by the company helped mitigate the threat.
  2. 2 Meanwhile, UK telecom giant TalkTalk investigates a potential data breach, raising alarm over customer data security. Collaborations with data protection authorities are underway to ensure legal compliance and protect client information.
  3. 3 A cyber threat looms as a hidden backdoor, triggered by a 'magic packet,' is detected within Juniper routers globally. This security flaw might allow unauthorized network access, prompting a race among experts to understand and resolve the issue effectively.

+2 more stories

Open briefing →

The rundown

  1. 1 Hacked dAily is your go-to source for the latest in cybersecurity, brought to you by Cytadel Cyber. Tune in daily to stay ahead of the cyber threats and trends shaping our digital landscape.
  2. 2 In today's episode, we start with the ongoing risk posed by unpatched Exchange Servers susceptible to ProxyLogon exploits, highlighting the critical need for prompt remediation in cybersecurity practices. We then delve into the world of cyber espionage, as hackers deploy the XWorm Trojan to hijack over 18,000 devices, targeting less-experienced hackers and illustrating an internal threat evolution among cybercriminals.
  3. 3 Next, we turn to some positive news as Amazon Web Services makes a bold move to fortify the UK's cybersecurity future. With a £5 million grant, AWS is advocating for enhanced cyber education, reaching out to underrepresented communities to cultivate a diverse and skilled technology workforce.

+1 more story

Open briefing →

The rundown

  1. 1 First up, cybersecurity experts discovered a shared codebase between Morpheus and HellCat ransomware payloads, suggesting possible links and coordinated efforts in the cyber threat landscape. This potential connection complicates defense strategies, as comprehensive measures may now be needed for protection against both variants.
  2. 2 In financial news, PayPal faces a $2 million fine from New York for failing to implement adequate security measures on its Venmo service, potentially violating consumer protection laws. The settlement pushes PayPal towards stricter security protocols and transparency with its users.
  3. 3 Privacy concerns rise as a bug in Cloudflare's CDN exposes user location data on secure messaging apps like Signal and Discord. The IP address logging issue prompts immediate action from involved platforms to restore privacy protections.

+2 more stories

Open briefing →

The rundown

  1. 1 In our top story, the UN Security Council is taking steps to tackle the growing global threat posed by commercial spyware. This marks the first time the council has discussed the issue, aiming to develop regulatory frameworks that balance human rights and national security.
  2. 2 Meanwhile, a $54 billion company is reeling after a ransomware attack. Quick action was taken to mitigate the damage, and authorities are investigating to prevent future breaches. This incident highlights the critical importance of robust cybersecurity protocols.
  3. 3 Cisco users, be aware! The company has released a vital patch for a high-severity vulnerability in its Meeting Management software. With a CVSS score of 9.9, this flaw allows attackers privileged access. Users should apply the update immediately to secure their systems.

+2 more stories

Open briefing →

The rundown

  1. 1 Our top story features T-Mobile’s strategic move to fortify its system security by acquiring over 200,000 YubiKeys. This initiative enhances protection against unauthorized access, reflecting the industry’s shift towards physical authentication and minimizing reliance on traditional passwords.
  2. 2 In investment news, Mitiga has raised an impressive $30 million in its Series B funding round. Led by ClearSky Security with investments from Samsung Next and Blackstone, this funding will help expand Mitiga's cloud and SaaS security solutions.
  3. 3 We also cover the unexpected global outage impacting Bitbucket, a key platform for source code management. This service disruption has left users seeking alternatives amidst the downtime, which has yet to receive a clear resolution.

+2 more stories

Open briefing →

The rundown

  1. 1 In today’s episode, we spotlight a concerning trend from the Indian APT group known as DONOT, which is abusing legitimate apps for espionage against entities in China and Pakistan. This highlights the inventive tactics of cyber threat actors who exploit everyday applications for malicious purposes.
  2. 2 Next, we delve into the alarming rise of phishing attacks dominating smartphone security. A recent survey shows that over 80% of mobile security incidents originate from phishing scams. As mobile usage skyrockets, protecting against these deceptive tactics has never been more critical.
  3. 3 We also explore Trend Micro's latest findings on the rise of infections from fake software installers and illegal software cracks. This report underscores the necessity of using legitimate software and strong security measures to fend off these growing cybersecurity threats.

+2 more stories

Open briefing →

The rundown

  1. 1 Today's episode kicks off with an update on TikTok's status in the United States. Former President Donald Trump has granted an extension, allowing the app more time amidst privacy and national security concerns, while negotiations for compliance with US regulations continue.
  2. 2 Next, we delve into a concerning breach at Hewlett Packard Enterprise. Hackers claim to have accessed sensitive data, now up for sale, prompting HPE to investigate and enhance security measures to mitigate potential risks for themselves and their clients.
  3. 3 We also discuss the temporary grounding of Sage's AI tool, Copilot, due to detected misbehavior. This pause ensured the system's integrity was restored, with services resuming shortly to support uninterrupted business operations.

+2 more stories

Open briefing →

The rundown

  1. 1 First, the United States is planning a federal ban on TikTok set for January 2025, following security concerns over data privacy and potential ties to the Chinese government, impacting millions of users and creators.
  2. 2 Next, the Federal Trade Commission has ordered General Motors to halt the collection and sale of drivers' personal data. This move aims to bolster consumer privacy protections amid worrying trends in digital data misuse.
  3. 3 The FBI has faced a security breach suspected to involve hacked phone logs, underscoring vulnerabilities in its communication systems and pushing for enhanced cybersecurity measures to safeguard sensitive information.

+2 more stories

Open briefing →

The rundown

  1. 1 In today's episode, we start with a massive data breach at Otelier, a travel tech company, exposing the personal details and hotel reservations of potentially millions. The root cause? A simple misconfiguration of their database.
  2. 2 Next, we dive into the realm of automated cyber attacks, as Python-based bots exploit vulnerabilities in PHP servers to proliferate illegal online gambling platforms. This highlights a concerning trend of using automation for malicious endeavors.
  3. 3 We then explore a novel technique used by cybercriminals: trojanized images. These seemingly harmless images carry hidden malware, showcasing the innovative tactics being deployed to bypass traditional security defenses.

+2 more stories

Open briefing →

The rundown

  1. 1 Today's top story focuses on a major legal battle as a European privacy advocacy group takes on TikTok and AliExpress. These platforms are accused of violating EU privacy laws by allegedly transferring user data to China, raising serious privacy concerns.
  2. 2 Next, we cover a sophisticated cyber attack affecting Gmail users. Hackers have found a way to compromise encryption keys, allowing them to access sensitive information. We discuss the implications and urge users to bolster their account security.
  3. 3 In another alarming development, 4.2 million internet hosts are vulnerable to hijacking due to bugs in tunneling protocols. This flaw could lead to massive data breaches and disrupted communications, highlighting the urgent need for patches.

+2 more stories

Open briefing →

The rundown

  1. 1 In today's episode, we dive into the shadowy world of quantum espionage, where Russian spies are targeting U.S. university labs to steal cutting-edge quantum computing research. This high-stakes "shadow war" has prompted the CIA and NSA to ramp up cybersecurity efforts to safeguard sensitive breakthroughs from falling into the wrong hands.
  2. 2 Next, we discuss the FortiGate device leak, where hackers have exposed configuration files and VPN credentials for 15,000 devices. This incident underscores the critical need for organizations to secure VPN configurations and regularly update hardware to prevent unauthorized access.
  3. 3 Then, we cover Salt Typhoon attacks, Chinese cyber campaigns targeting U.S. telecommunications. CISA’s coordinated response highlights the ongoing challenges of securing critical infrastructure against advanced foreign threats, especially in the face of outdated technology vulnerabilities.

+3 more stories

Open briefing →

The rundown

  1. 1 In today's episode, we delve into a recent discovery of a security flaw within Google's OAuth system. This vulnerability could allow attackers to exploit abandoned accounts due to weak token management practices. We highlight the critical need for effective token management policies to protect user data.
  2. 2 Next, we discuss the FBI's successful operation against PlugX malware. After months of investigation, the agency has eradicated this remote access threat from over 4,250 compromised systems in the U.S., offering enhanced security and peace of mind to thousands of affected users.
  3. 3 Then, we cover Snyk's clarification on seemingly malicious packages found on the NPM registry. These packages were part of a controlled research effort to shed light on security vulnerabilities, promoting awareness and better practices in package management.

+2 more stories

Open briefing →

The rundown

  1. 1 A significant breach has struck Telefonica’s ticketing system, following an attack by infostealer malware that exploited stolen credentials. This incident emphasizes the critical vulnerabilities organizations face and the necessity to fortify cybersecurity defenses.
  2. 2 The International Civil Aviation Organization (ICAO) faces a potential cybersecurity breach from a notorious cybercriminal group, with claims of up to 42,000 sensitive documents being compromised. This event adds to a streak of cyberattacks on UN agencies, urging a call for reinforced security practices.
  3. 3 UK Domain Registry Nominet has encountered a cyber threat via a zero-day vulnerability in Ivanti's VPN software, potentially involving Chinese state-sponsored hackers. While no data theft has been confirmed, Nominet is actively enhancing security and investigating the incident alongside experts.

+1 more story

Open briefing →

The rundown

  1. 1 In today's episode:
  2. 2 Our top story delves into a disturbing discovery where expired domains are being used to control over 4,000 backdoors on compromised systems. These vulnerabilities put sensitive data at risk as cybercriminals exploit under-the-radar access points.
  3. 3 In WordPress news, a new threat has emerged with cybercriminals injecting skimmers directly into database tables. This advanced method bypasses usual detection tactics, making it easier for hackers to siphon off payment details without leaving digital footprints.

+3 more stories

Open briefing →

The rundown

  1. 1 Firstly, cyber experts have uncovered a phishing campaign where attackers disguise themselves as CrowdStrike recruiters, distributing malware via fake job offers. This underlines the critical need for vigilance when receiving unsolicited communications.
  2. 2 Next, a deceptive GitHub repository claiming to be an LDAPNightmare exploit is instead spreading Infostealer malware, highlighting the abuse of trusted platforms by malicious actors. Users are advised to exercise caution and verify the authenticity of software tools before use.
  3. 3 In another significant development, Microsoft is taking legal action against a hacking group accused of misusing Azure's AI for generating harmful content. This lawsuit emphasizes Microsoft's dedication to protecting its customer's data and ensuring the security of its AI services.

+2 more stories

Open briefing →

The rundown

  1. 1 In today's top story, Apple's latest innovation, the ACE3 USB-C controller in the iPhone 15 series, faces a security breach. Researchers have hacked through Apple's enhanced defenses using advanced techniques like RF side-channel analysis, challenging the robustness of even top-tier device security.
  2. 2 Next, the Department of Justice charges three Russian nationals with operating crypto mixing services linked to large-scale cybercrimes. Bitzlato and Hydra's operations processed billions linked to illicit activities, as legal efforts intensify against cybercrime financing.
  3. 3 We also explore Microsoft's decision to automatically install the new Outlook on Windows 10 PCs starting February. Aimed at enhancing user efficiency, this transition reflects Microsoft's goal of unifying and streamlining their productivity tools.

+2 more stories

Open briefing →

The rundown

  1. 1 In today's top story, a Chinese advanced persistent threat group has mounted a sophisticated espionage campaign targeting Japan. This operation has compromised sensitive data across sectors such as defense and finance, highlighting the ongoing cybersecurity tensions between the two nations.
  2. 2 Meanwhile, a federal judge has allowed a class-action lawsuit against Google to proceed, as users allege privacy violations while browsing in "incognito" mode. Google's failed attempt to dismiss the case brings data privacy issues into the legal spotlight.
  3. 3 In the tech world, security researchers have identified a new malware strain, Banshee 2.0, that cleverly uses Apple's encryption methods to bypass Mac's defenses. This threat underscores the challenges in safeguarding devices against sophisticated attacks leveraging legitimate software features.

+2 more stories

Open briefing →

The rundown

  1. 1 First up, a clever phishing scam is capturing PayPal users off guard. Attackers are sending emails from genuine-looking PayPal addresses, tricking recipients into sharing personal information. Stay alert, check email authenticity, and refrain from clicking dubious links.
  2. 2 Next, Gravy Analytics is scrambling after a potential data breach. Millions of users' location data may have been exposed, potentially endangering privacy. This breach highlights the critical importance of data security and regulatory compliance.
  3. 3 Meanwhile, scams targeting individuals with fake bank and government officials are escalating. These fraudsters persuade victims to install remote access apps to steal OTPs, compromising bank accounts. Authorities urge you to protect your personal information.

+2 more stories

Open briefing →

The rundown

  1. 1 In today's episode: The UK government is pushing back against the misuse of digital imaging technology, particularly the creation and spread of sexually explicit deepfakes without consent. The new law aims to safeguard privacy and provide legal avenues to combat non-consensual intimate image abuse.
  2. 2 We'll also cover a significant breach involving the PowerSchool platform, compromising data from K-12 schools. The quest to uncover the breach's full implications is underway as officials bolster cybersecurity to protect sensitive data.
  3. 3 The Cybersecurity and Infrastructure Security Agency (CISA) alerts organizations to critical vulnerabilities in Mitel and Oracle systems. These security flaws, if unaddressed, could result in unauthorized access and operational disruptions, underscoring the urgent need for system updates.

+2 more stories

Open briefing →
Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.