Skip to content
Hacked dAily
All Episodes

Hacked dAily Episodes

Every episode of Hacked dAily: 558 daily cybersecurity briefings and counting. Breaking news on breaches, ransomware and AI threats. Page 23 of 24.

The rundown

  1. 1 Today’s lineup includes a tale of classic misdirection as authorities finally apprehend the Houdini of hackers responsible for over 40 cyberattacks. High security? More like high collar now! Meanwhile, in a chapter ripped straight from a spy novel, we uncover DeepSeek's chatbot ties to a Chinese telecom that the USA would rather ghost than follow on social media.
  2. 2 Cybercriminals have also upped their game, launching a 13 million password spraying extravaganza using Go Resty and Node Fetch. Open-source software users, time to change your passwords from "letmein" to "somethingActuallySecure"!
  3. 3 In other news, the Phorpiex botnet resurfaces like the undead in a horror flick, delivering ransomware with the efficiency of a drone delivery service.

+1 more story

Open briefing →

The rundown

  1. 1 Today, we dive into Amazon Redshift's new default breach deterrents. They're wrapping your data tighter than the crown jewels. Ever curious about "non-default" security? Maybe it's just for the thrill-seekers out there.
  2. 2 Next, our favorite digital villains, Crazy Evil, are skipping Netflix password drama and going straight for a high-stakes heist, the crypto kind. Their malware arsenal is as impressive as a blockbuster movie plot, except it's your currency they're after.
  3. 3 Then, in the ongoing saga of cybersecurity versus hackers, a sophisticated phishing attack just bypassed Microsoft's ADFS Multi-Factor Authentication. It appears hackers view MFA as a friendly suggestion rather than a security measure. Microsoft’s digital sigh is almost audible as they scramble to play whack-a-mole.

+2 more stories

Open briefing →

The rundown

  1. 1 Moving on, Microsoft saves the day by patching a flaw in its SharePoint Connector before it could become a cyber pickpocket's playground, because who needs more uninvited guests when you're already running out of snacks?
  2. 2 Meanwhile, cybersecurity analysts are raising eyebrows over "FlexibleFerret," a mischievous new variant in the DPRK malware family. North Korea might need a new hobby, but hey, their ferret-like stealth is undeniably impressive, if only they devoted the same energy to meme-worthy dance routines.
  3. 3 In other news, a ransomware attack at a hospital left expectant mothers needing not just an epidural, but perhaps digital anesthesia as well. Who knew network downtime could rival labor pain?
Open briefing →

The rundown

  1. 1 Then, we visit the world's wackiest sitcom, Big Tech vs. Hackers. This episode features Microsoft's ad accounts being abducted via malicious Google Ads. Until there's peace on all advertising fronts, we'll stick to our "Skip Ad" mantra like it's a new religion.
  2. 2 Next, it's an international escapade as U.S. and Dutch officials seize 39 domains from Pakistan's HeartSender. Selling phishing kits with neon flair, they're now gracefully bowing out. Beware, they've hidden a behind-the-scenes blooper reel, check if you’re in it!
  3. 3 Say hello again to simpler times with WannaCry ransomware. Despite being old as a classic rock band, it revived nostalgia with a well-preserved knack for chaos, targeting NAS drives like a perpetually looping reunion tour.

+1 more story

Open briefing →

The rundown

  1. 1 First up, we explore how AngelSense turned their server into a digital public square, because who doesn't like to share sensitive data with the whole world? Remember, security folks, a little server check-up never hurt anyone, just like eating your veggies, but for techies.
  2. 2 Then, in the land where the stars at night are big and bright, Governor Greg Abbott has thrown down the ban hammer on DeepSeek and RedNote. Texas government staff may need to adjust to working without that perfect office jam or knowledge binges, maybe productivity will see a boost.
  3. 3 In a plot twist that almost sounds exciting enough for Netflix, Casio and 16 websites found themselves unwitting contestants in a web-skimming thriller. It’s Excel but with a sinister twist; who knew spreadsheets could be scary?

+2 more stories

Open briefing →

The rundown

  1. 1 First off, Google's g.co takes a hit with a stealthy phishing attack. Remember, when “Chloe from Google” calls, it’s usually less about security and more about your credit card details. Maybe take their tips on holding suspicious codes with a grain of salt – or a cup of common sense.
  2. 2 Meanwhile, a jailbreak named "Time Bandit" outsmarts ChatGPT, making AI's ironclad security look more like a foam sword. If AI were a parent, "Time Bandit" is definitely that rebellious kid sneaking strategic hacks past the curfew.
  3. 3 In other riveting news, VMware continues its perpetual game of digital whack-a-mole, patching vulnerabilities faster than a cat video goes viral. Kudos for keeping hackers’ dreams in drafts – for now.

+2 more stories

Open briefing →

The rundown

  1. 1 First up, Aquabotv3 malware has mastered the art of command injection on Mitel systems. Think of it as hackers finding themselves an all-access pass to the most exclusive concert: Your sensitive data. IT departments contemplate their next move, bolster defenses or perhaps take up ballroom dancing lessons to skillfully dodge the next digital breach.
  2. 2 Next, Lazarus Group, the internet’s favorite band of cybercriminals, indulges in a React-based admin panel facelift, because even law-breakers value a sleek user interface. Is a chatbot for customer complaints next on their to-do list? Stay tuned to find out.
  3. 3 Wacom users, take heed, your credit card details may have been the subject of some unsanctioned artistic expression. While their drawing tablets capture the finer details, so might your stolen credentials. Worry not, Wacom promises no sequels to this thriller and is busy cleaning up the mess.

+2 more stories

Open briefing →

The rundown

  1. 1 First up, cyber scammers are getting spicy with "hidden text salting," seasoning their emails to trick even the sharpest spam filters. It's like adding grandma's secret spicy ingredient to an otherwise bland meal… or in this case, phishing emails. For those still believing in Nigerian princes, switching to carrier pigeons might be an upgrade!
  2. 2 Next, be cautious of the new phishing flavor of the day: Amazon-branded PDFs. Don’t fall for it faster than a Black Friday deal! If it's too good to be true, it probably wants your credit card info.
  3. 3 Deep in "SimpleHelp" territory, hackers are exploiting its Remote Monster, sorry, Monitoring and Management, proving yet again that simplicity may actually be the mother of network invasions.

+2 more stories

Open briefing →

The rundown

  1. 1 First up, Apple flexes its security muscles yet again, patching up a pesky zero-day vulnerability as if it's just another day at the tech fortress. Next, we slide over to the British Museum, where the plot seems straight out of a spy film, an inside job amidst the mummies and artifacts. Who knew betrayal was lurking just a cubicle away?
  2. 2 From ancient relics to digital wallets, Phemex users are having an expensive wake-up call after a $69 million heist, proving the crypto world can spin narratives crazier than a Hollywood movie. Meanwhile, over in Wood County, the IT director has resigned after a $1.5 million ransomware fiasco, maybe considering a career in avoiding phishing scams instead.
  3. 3 Finally, DeepSeek emerges from China, boasting AI search speeds faster than a toddler can lose interest. Google's monopoly might consider taking some kung fu lessons because, let's face it, their Mandarin might be rusty.
Open briefing →

The rundown

  1. 1 First up, Meta's Llama framework finds itself with an open door for remote code execution risks. It's like inviting AI systems to an all-you-can-hack buffet. Meta, maybe it's time to hire a virtual bouncer?
  2. 2 Next, the cyber curveball: The mischievous MintsLoader group is rolling out StealC malware and BOINC, as smoothly as a pizza delivery guy interrupting your binge-watch session. Grab your popcorn; this cyber heist promises a ton of suspense!
  3. 3 Meanwhile, Cobalt Strike and SOCKS proxies are channeling their inner Bonnie and Clyde as they usher in LockBit ransomware, with less-than-stellar customer service skills. These bad guys are the modern equivalent of an IT department gone rogue, showcasing their misplaced talents.

+2 more stories

Open briefing →

The rundown

  1. 1 In today's top stories: Subaru swiftly addresses a security vulnerability in their Starlink connected vehicle service, which posed risks of remote hacking and exposure of sensitive data for cars across the U.S., Canada, and Japan. Quick action by the company helped mitigate the threat.
  2. 2 Meanwhile, UK telecom giant TalkTalk investigates a potential data breach, raising alarm over customer data security. Collaborations with data protection authorities are underway to ensure legal compliance and protect client information.
  3. 3 A cyber threat looms as a hidden backdoor, triggered by a 'magic packet,' is detected within Juniper routers globally. This security flaw might allow unauthorized network access, prompting a race among experts to understand and resolve the issue effectively.

+2 more stories

Open briefing →

The rundown

  1. 1 Hacked dAily is your go-to source for the latest in cybersecurity, brought to you by Cytadel Cyber. Tune in daily to stay ahead of the cyber threats and trends shaping our digital landscape.
  2. 2 In today's episode, we start with the ongoing risk posed by unpatched Exchange Servers susceptible to ProxyLogon exploits, highlighting the critical need for prompt remediation in cybersecurity practices. We then delve into the world of cyber espionage, as hackers deploy the XWorm Trojan to hijack over 18,000 devices, targeting less-experienced hackers and illustrating an internal threat evolution among cybercriminals.
  3. 3 Next, we turn to some positive news as Amazon Web Services makes a bold move to fortify the UK's cybersecurity future. With a £5 million grant, AWS is advocating for enhanced cyber education, reaching out to underrepresented communities to cultivate a diverse and skilled technology workforce.

+1 more story

Open briefing →

The rundown

  1. 1 First up, cybersecurity experts discovered a shared codebase between Morpheus and HellCat ransomware payloads, suggesting possible links and coordinated efforts in the cyber threat landscape. This potential connection complicates defense strategies, as comprehensive measures may now be needed for protection against both variants.
  2. 2 In financial news, PayPal faces a $2 million fine from New York for failing to implement adequate security measures on its Venmo service, potentially violating consumer protection laws. The settlement pushes PayPal towards stricter security protocols and transparency with its users.
  3. 3 Privacy concerns rise as a bug in Cloudflare's CDN exposes user location data on secure messaging apps like Signal and Discord. The IP address logging issue prompts immediate action from involved platforms to restore privacy protections.

+2 more stories

Open briefing →

The rundown

  1. 1 In our top story, the UN Security Council is taking steps to tackle the growing global threat posed by commercial spyware. This marks the first time the council has discussed the issue, aiming to develop regulatory frameworks that balance human rights and national security.
  2. 2 Meanwhile, a $54 billion company is reeling after a ransomware attack. Quick action was taken to mitigate the damage, and authorities are investigating to prevent future breaches. This incident highlights the critical importance of robust cybersecurity protocols.
  3. 3 Cisco users, be aware! The company has released a vital patch for a high-severity vulnerability in its Meeting Management software. With a CVSS score of 9.9, this flaw allows attackers privileged access. Users should apply the update immediately to secure their systems.

+2 more stories

Open briefing →

The rundown

  1. 1 Our top story features T-Mobile’s strategic move to fortify its system security by acquiring over 200,000 YubiKeys. This initiative enhances protection against unauthorized access, reflecting the industry’s shift towards physical authentication and minimizing reliance on traditional passwords.
  2. 2 In investment news, Mitiga has raised an impressive $30 million in its Series B funding round. Led by ClearSky Security with investments from Samsung Next and Blackstone, this funding will help expand Mitiga's cloud and SaaS security solutions.
  3. 3 We also cover the unexpected global outage impacting Bitbucket, a key platform for source code management. This service disruption has left users seeking alternatives amidst the downtime, which has yet to receive a clear resolution.

+2 more stories

Open briefing →

The rundown

  1. 1 In today’s episode, we spotlight a concerning trend from the Indian APT group known as DONOT, which is abusing legitimate apps for espionage against entities in China and Pakistan. This highlights the inventive tactics of cyber threat actors who exploit everyday applications for malicious purposes.
  2. 2 Next, we delve into the alarming rise of phishing attacks dominating smartphone security. A recent survey shows that over 80% of mobile security incidents originate from phishing scams. As mobile usage skyrockets, protecting against these deceptive tactics has never been more critical.
  3. 3 We also explore Trend Micro's latest findings on the rise of infections from fake software installers and illegal software cracks. This report underscores the necessity of using legitimate software and strong security measures to fend off these growing cybersecurity threats.

+2 more stories

Open briefing →

The rundown

  1. 1 Today's episode kicks off with an update on TikTok's status in the United States. Former President Donald Trump has granted an extension, allowing the app more time amidst privacy and national security concerns, while negotiations for compliance with US regulations continue.
  2. 2 Next, we delve into a concerning breach at Hewlett Packard Enterprise. Hackers claim to have accessed sensitive data, now up for sale, prompting HPE to investigate and enhance security measures to mitigate potential risks for themselves and their clients.
  3. 3 We also discuss the temporary grounding of Sage's AI tool, Copilot, due to detected misbehavior. This pause ensured the system's integrity was restored, with services resuming shortly to support uninterrupted business operations.

+2 more stories

Open briefing →

The rundown

  1. 1 First, the United States is planning a federal ban on TikTok set for January 2025, following security concerns over data privacy and potential ties to the Chinese government, impacting millions of users and creators.
  2. 2 Next, the Federal Trade Commission has ordered General Motors to halt the collection and sale of drivers' personal data. This move aims to bolster consumer privacy protections amid worrying trends in digital data misuse.
  3. 3 The FBI has faced a security breach suspected to involve hacked phone logs, underscoring vulnerabilities in its communication systems and pushing for enhanced cybersecurity measures to safeguard sensitive information.

+2 more stories

Open briefing →

The rundown

  1. 1 In today's episode, we start with a massive data breach at Otelier, a travel tech company, exposing the personal details and hotel reservations of potentially millions. The root cause? A simple misconfiguration of their database.
  2. 2 Next, we dive into the realm of automated cyber attacks, as Python-based bots exploit vulnerabilities in PHP servers to proliferate illegal online gambling platforms. This highlights a concerning trend of using automation for malicious endeavors.
  3. 3 We then explore a novel technique used by cybercriminals: trojanized images. These seemingly harmless images carry hidden malware, showcasing the innovative tactics being deployed to bypass traditional security defenses.

+2 more stories

Open briefing →

The rundown

  1. 1 Today's top story focuses on a major legal battle as a European privacy advocacy group takes on TikTok and AliExpress. These platforms are accused of violating EU privacy laws by allegedly transferring user data to China, raising serious privacy concerns.
  2. 2 Next, we cover a sophisticated cyber attack affecting Gmail users. Hackers have found a way to compromise encryption keys, allowing them to access sensitive information. We discuss the implications and urge users to bolster their account security.
  3. 3 In another alarming development, 4.2 million internet hosts are vulnerable to hijacking due to bugs in tunneling protocols. This flaw could lead to massive data breaches and disrupted communications, highlighting the urgent need for patches.

+2 more stories

Open briefing →

The rundown

  1. 1 In today's episode, we dive into the shadowy world of quantum espionage, where Russian spies are targeting U.S. university labs to steal cutting-edge quantum computing research. This high-stakes "shadow war" has prompted the CIA and NSA to ramp up cybersecurity efforts to safeguard sensitive breakthroughs from falling into the wrong hands.
  2. 2 Next, we discuss the FortiGate device leak, where hackers have exposed configuration files and VPN credentials for 15,000 devices. This incident underscores the critical need for organizations to secure VPN configurations and regularly update hardware to prevent unauthorized access.
  3. 3 Then, we cover Salt Typhoon attacks, Chinese cyber campaigns targeting U.S. telecommunications. CISA’s coordinated response highlights the ongoing challenges of securing critical infrastructure against advanced foreign threats, especially in the face of outdated technology vulnerabilities.

+3 more stories

Open briefing →

The rundown

  1. 1 In today's episode, we delve into a recent discovery of a security flaw within Google's OAuth system. This vulnerability could allow attackers to exploit abandoned accounts due to weak token management practices. We highlight the critical need for effective token management policies to protect user data.
  2. 2 Next, we discuss the FBI's successful operation against PlugX malware. After months of investigation, the agency has eradicated this remote access threat from over 4,250 compromised systems in the U.S., offering enhanced security and peace of mind to thousands of affected users.
  3. 3 Then, we cover Snyk's clarification on seemingly malicious packages found on the NPM registry. These packages were part of a controlled research effort to shed light on security vulnerabilities, promoting awareness and better practices in package management.

+2 more stories

Open briefing →

The rundown

  1. 1 A significant breach has struck Telefonica’s ticketing system, following an attack by infostealer malware that exploited stolen credentials. This incident emphasizes the critical vulnerabilities organizations face and the necessity to fortify cybersecurity defenses.
  2. 2 The International Civil Aviation Organization (ICAO) faces a potential cybersecurity breach from a notorious cybercriminal group, with claims of up to 42,000 sensitive documents being compromised. This event adds to a streak of cyberattacks on UN agencies, urging a call for reinforced security practices.
  3. 3 UK Domain Registry Nominet has encountered a cyber threat via a zero-day vulnerability in Ivanti's VPN software, potentially involving Chinese state-sponsored hackers. While no data theft has been confirmed, Nominet is actively enhancing security and investigating the incident alongside experts.

+1 more story

Open briefing →
Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.