Skip to content
Hacked dAily
All Episodes

Hacked dAily Episodes

Every episode of Hacked dAily: 500 daily cybersecurity briefings and counting. Breaking news on breaches, ransomware and AI threats. Page 3 of 21.

The rundown

  1. 1 In today's top stories:
  2. 2 A corporate data breach via an internet-connected coffee machine highlights the vulnerabilities of IoT devices. Cybercriminals accessed the network through the appliance, stressing the essential need for stringent security on all connected devices to safeguard sensitive data.
  3. 3 Italy's Uffizi Gallery reported a cyberattack with no significant data compromise, spotlighting the cyber challenges cultural institutions face in safeguarding digital assets against increasing threats.

+4 more stories

Open briefing →

The rundown

  1. 1 A breach exposed vulnerabilities in npm's open-source ecosystem after an attacker used a fake Microsoft Teams prompt to control the popular Axios library. This stresses the need for stronger authentication and vigilance against phishing to protect software supply chains.
  2. 2 Crunchyroll faces a data breach, compromising over a million accounts and highlighting vulnerabilities in digital platforms and the importance of robust cybersecurity measures to protect user data and maintain trust.
  3. 3 A discovered vulnerability in the Mongoose web server software allows potential remote code execution on IoT devices, risking unauthorized access. This flaw could disrupt systems globally, underscoring the need for prompt security patches.

+2 more stories

Open briefing →

The rundown

  1. 1 ICE's use of Paragon spyware has ignited debates on constitutional compliance, civil liberties, and counterintelligence. With calls for transparency, the controversy signals potential national security implications.
  2. 2 Over 14,000 F5 BIG-IP APM instances remain unpatched, exposing businesses to RCE attacks. This highlights the pressing need for rigorous patch management and proactive defense strategies.
  3. 3 Google researchers reveal "Coruna," an iPhone hacking toolkit exploiting 23 iOS vulnerabilities, allegedly used by Russia. This discovery raises alarms about the spread and control of state-sponsored cyber tools.

+3 more stories

Open briefing →

The rundown

  1. 1 The FBI warns against Chinese mobile apps due to serious privacy and security risks, highlighting concerns about possible unauthorized data access and espionage, emphasizing the need for vigilance in app selection amidst geopolitical tensions.
  2. 2 ShinyHunters claims a major breach at Cisco Systems, involving over 3 million Salesforce records linked to high-profile entities like the FBI, IRS, and NASA. This raises alarms about potential targeted attacks, urging heightened security measures for companies using Salesforce.
  3. 3 The emergence of EvilTokens exacerbates phishing attacks on Microsoft device codes, allowing cybercriminals to bypass two-factor authentication. This trend underscores the need for enhanced security protocols against sophisticated token-based threats.

+2 more stories

Open briefing →

The rundown

  1. 1 Dubai International Airport faces claims of a data breach by Nasir Security, allegedly infiltrating the hub's intelligence systems. This breach could pose severe security risks and privacy threats, emphasizing vulnerabilities in global infrastructure.
  2. 2 A new service helps ransomware gangs monetize stolen data, heightening financial and reputational risks for victims. This reveals a complex threat landscape, urging stronger cybersecurity defenses and response plans.
  3. 3 Lloyds Banking Group's IT glitch exposed sensitive data of nearly 500,000 customers, highlighting severe data privacy issues and potential regulatory scrutiny. Institutions must enhance cybersecurity to prevent such breaches.

+2 more stories

Open briefing →

The rundown

  1. 1 Today, discover how Google’s new feature in Google Drive for desktop automatically scans for ransomware threats, bolstering defenses as ransomware attacks surge globally.
  2. 2 A dark web listing claims possession of 375 terabytes of data from Lockheed Martin, priced at $600 million. This could have severe national security implications, emphasizing the vulnerability of defense contractors.
  3. 3 Researchers reveal the TeamPCP group’s exploitation of a tainted Telnyx SDK to steal credentials via a fake ringtone file. This highlights the importance of maintaining third-party software integrity.

+3 more stories

Open briefing →

The rundown

  1. 1 Today, the U.S. government's ban on foreign-made routers in critical infrastructure has sparked industry debate. Critics argue it's less about security and more about protecting domestic manufacturers, potentially affecting trade and technological innovation.
  2. 2 A vulnerability in the Smart Slider plugin threatens over 500,000 WordPress sites by potentially exposing sensitive files. This highlights the need for regular plugin updates and rigorous security reviews to protect digital assets.
  3. 3 EtherRAT’s integration with the Ethereum blockchain in the EtherHiding technique is transforming cyber threat landscapes. This method complicates detection and stresses the importance of staying updated on sophisticated threats leveraging decentralized networks.

+3 more stories

Open briefing →

The rundown

  1. 1 FBI Director Christopher Wray's personal data was reportedly compromised by the cyber group Handala as part of an offensive targeting high-profile officials. This breach signifies growing cyber threats at national security levels, urging enhanced protective strategies for government leaders.
  2. 2 Apple warns users of older iPhones and iPads about active exploits. Critical updates are necessary as outdated devices remain vulnerable to attacks like Coruna and DarkSword, stressing the crucial nature of regular software updates.
  3. 3 TA446's spear-phishing campaign leverages the DarkSword iOS Exploit Kit, aiming at high-value targets. This marks a significant evolution in threat actor strategies, necessitating increased vigilance and protective measures for both organizations and individuals.

+3 more stories

Open briefing →

The rundown

  1. 1 Today's top stories include a cyberattack on the European Commission's cloud systems, resulting in unauthorized data access and highlighting cybersecurity challenges for EU entities. In the Netherlands, a phishing attack breached the Dutch Police, emphasizing the pressing need for robust cybersecurity and employee training to prevent national security risks.
  2. 2 A fraudulent website mimicking Avast has been reported, tricking users into downloading the Venom Stealer malware, underscoring the importance of vigilance against phishing scams exploiting trusted brands. South Korean AI company ActionPower faces an attack from the Crypto24 group, spotlighting ransomware risks that threaten tech firms with operational disruptions.
  3. 3 Lastly, the "Mythos leak" at Anthropic brings attention to Phishing 3.0, a sophisticated cyberattack evolution demanding advanced security strategies from organizations.

+1 more story

Open briefing →

The rundown

  1. 1 Apple's latest iOS update mandates age verification for UK users, sparking privacy concerns by requiring personal data to access specific apps. Critics liken this move to 'ransomware,' citing major implications under the UK’s Online Safety Act.
  2. 2 Google predicts quantum computers could break current encryption by 2029, threatening global data security. This highlights the urgent need for quantum-resistant algorithms to protect sensitive digital assets.
  3. 3 Ajax Football Club suffers a cyberattack, compromising fans’ personal data and ticketing systems. The breach underscores sports organizations' need for strong cybersecurity to safeguard data integrity and reputation.

+3 more stories

Open briefing →

The rundown

  1. 1 Today’s top story: Baltimore sues Elon's xAI for allegedly distributing deepfake videos, spotlighting the challenges and potential legal ramifications of AI technologies in spreading disinformation.
  2. 2 The National Association on Drug Abuse Problems reports a breach impacting 90,000 individuals, exposing sensitive personal data. The incident urges the need for heightened cybersecurity and consumer vigilance.
  3. 3 Silver Fox campaigns adopt dual espionage tactics, blending cyber and human intelligence. This evolution stresses the importance of comprehensive defenses against both digital and human intelligence threats.

+3 more stories

Open briefing →

The rundown

  1. 1 Microsoft warns of a sophisticated phishing campaign exploiting Remote Monitoring and Management software, targeting 29,000 users by posing as the IRS. This emphasizes the urgent need for robust cybersecurity defenses against deceptive tactics.
  2. 2 Authorities dismantled 373,000 dark web sites engaged in hosting child sexual abuse material. This highlights the need for international collaboration and advanced enforcement to combat cybercrime effectively.
  3. 3 Mazda disclosed a data breach from unauthorized access to its warehouse management system, impacting 692 employee and partner records. The incident underscores the importance of addressing security vulnerabilities and the repercussions of data exposure.

+2 more stories

Open briefing →

The rundown

  1. 1 Foster City, California, reels from a ransomware attack disrupting municipal services, highlighting the vulnerability of smaller municipalities to cyber threats. A state of emergency has been declared, emphasizing the importance of robust defenses for public entities against data breaches.
  2. 2 A new malware strain targets Cobra DocGuard users by disguising as legitimate documents, compromising sensitive data. Organizations must enhance security measures to protect critical data environments from these deceptive threats.
  3. 3 The GlassWorm cyber campaign exploits the Open VSX registry with sleeper extensions resembling Visual Studio Code enhancements, raising alarms over open-source security. This case underscores the need for vigilant monitoring of software repositories globally.

+3 more stories

Open briefing →

The rundown

  1. 1 Our top story covers a global hacking campaign that defaced over 7,500 Magento sites, affecting high-profile entities like Toyota and FedEx, highlighting risks in using prevalent web platforms.
  2. 2 We also discuss CVE-2026-33017, a critical Langflow vulnerability exploited within 20 hours of disclosure, underscoring the critical need for urgent patch management to protect infrastructures.
  3. 3 Another development involves attackers leveraging GitHub Actions to spread infostealer malware via the Trivy vulnerability scanner, stressing importance in securing CI/CD pipelines from supply chain attacks.

+3 more stories

Open briefing →

The rundown

  1. 1 Google has set a 24-hour delay on sideloading unverified apps on Android, aimed at reducing malware risks and protecting users from scams. This proactive measure reinforces Google's dedication to enhancing user security.
  2. 2 Three individuals face charges for attempting to export AI tech to China, spotlighting national security concerns over tech proliferation. This case emphasizes the necessity of stringent export controls in safeguarding U.S. innovations in AI.
  3. 3 A UK police force suspends live facial recognition technology amidst findings of racial bias, igniting debates on its ethical and fair use. This underscores the critical need for oversight in deploying surveillance technologies equitably.

+3 more stories

Open briefing →

The rundown

  1. 1 Google introduces "Install Unknown Apps" for Android, offering flexibility for advanced users while managing security risks through layered permissions and warnings. This approach seeks to empower users responsibly without compromising device security.
  2. 2 Hackers are exploiting browser prompts to phish for biometric data, creating a new avenue for digital theft. This tactic urges organizations to bolster security protocols and educate users to counteract deceptive threats effectively.
  3. 3 Security experts identify 54 EDR killers using BYOVD tactics to exploit driver vulnerabilities for privilege escalation. Enterprises must rigorously vet driver updates to protect against these sophisticated security breaches.

+3 more stories

Open briefing →

The rundown

  1. 1 Nordstrom's recent breach involved unauthorized use of their email system to distribute cryptocurrency scams, risking customer trust. This highlights the need for stringent email security measures to protect corporate reputation.
  2. 2 Cisco's firewall zero-day vulnerability has been exploited to deploy Interlock ransomware, underscoring the urgency for immediate patching and robust defenses. Businesses must stay vigilant against evolving threats to maintain security.
  3. 3 A potent .NET AOT malware variant uses black box techniques, complicating detection and analysis. This advancement in malware evasion calls for enhanced cybersecurity detection capabilities.

+3 more stories

Open briefing →

The rundown

  1. 1 Today's top story reveals a significant misstep by Fancy Bear (APT28), a Russian cyber-espionage group, which inadvertently exposed their hacking techniques and infrastructure. This operational security failure allows cybersecurity defenders to enhance defenses against sophisticated cyber threats.
  2. 2 The UK Companies House incident exposed sensitive data of millions of firms, highlighting severe data privacy concerns and the potential for identity theft and financial loss, stressing the importance of robust corporate data protection measures.
  3. 3 INTERPOL warns of cybercriminals increasingly using artificial intelligence to improve the effectiveness of scams, including phishing, deepfake videos, and voice cloning, posing a severe threat and necessitating advanced defense mechanisms.

+2 more stories

Open briefing →

The rundown

  1. 1 Today's top stories:
  2. 2 A security flaw in AWS Bedrock's code interpreter could let attackers execute unauthorized code. This highlights the urgent need for robust cloud security measures to protect data integrity and maintain user trust.
  3. 3 The "Zombie ZIP" tactic manipulates ZIP file headers to evade antivirus software. Despite being dubbed CVE-2026-0866, it poses a minimal risk to isolated systems, as detection remains possible post-decompression.

+4 more stories

Open briefing →

The rundown

  1. 1 A major flaw in Bluetooth mesh networking via BitChat reveals potential cache poisoning and replay attacks. These vulnerabilities threaten secure IoT communications, emphasizing the necessity for immediate patches to protect private data integrity.
  2. 2 "CrackArmor" has been unveiled as a threat to systems using AppArmor, risking local privilege escalation to root. Local attacks jeopardize the security of Linux-based systems, pressing the need for urgent updates to preserve system integrity.
  3. 3 Operation CamelClone, a cyber espionage effort, targets global government and defense sectors. State-sponsored actors aim to access classified data, highlighting the urgent requirement for international cybersecurity cooperation.

+3 more stories

Open briefing →

The rundown

  1. 1 The FBI is facing scrutiny after a breach involving files linked to Jeffrey Epstein, reportedly caused by human error, raising fresh concerns about the protection of highly sensitive federal data.
  2. 2 Storm-2561 is targeting corporate users through fake VPN websites and trojanized installers, showing how search manipulation and trusted software impersonation remain effective tools for credential theft.
  3. 3 Researchers have identified new PhantomRaven attack waves targeting the npm ecosystem, underscoring the continued risk of software supply chain compromise for developers and organizations relying on open-source packages.

+3 more stories

Open briefing →

The rundown

  1. 1 Starbucks faces a breach impacting 889 employees, highlighting persistent credential theft risks and stressing enhanced data protection beyond perimeter defenses to prevent long-term fraud and identity theft.
  2. 2 Telus Digital confirms a breach by ShinyHunters, notorious for major data heists, emphasizing the critical need for robust cybersecurity to protect customer information and maintain compliance and trust.
  3. 3 Stryker's global cyber attack reveals vulnerabilities in healthcare's digital infrastructure, stressing the pressing need for enhanced security measures to protect patient data and ensure operational integrity.

+3 more stories

Open briefing →

The rundown

  1. 1 Meta has fortified anti-scam tools on WhatsApp, Facebook, and Messenger, targeting sophisticated fraud like brand spoofing and account hijacking. This move seeks to enhance user protection amidst intensifying regulatory scrutiny over $13.7 billion in cyber fraud cases.
  2. 2 Hackers exploit Cloudflare's CAPTCHA to mask phishing pages as real Microsoft 365 logins, posing severe risks to organizations reliant on email filters. This method elevates phishing credibility, stressing the need for advanced threat detection.
  3. 3 Loblaw discloses a breach in its PC Optimum loyalty program, leading to unauthorized personal data access while financial details remain secure. This highlights the necessity of robust cybersecurity in protecting consumer data.

+3 more stories

Open briefing →
Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.