Skip to content
Hacked dAily
All Episodes

Hacked dAily Episodes

Every episode of Hacked dAily: 558 daily cybersecurity briefings and counting. Breaking news on breaches, ransomware and AI threats. Page 3 of 24.

The rundown

  1. 1 AI-enabled attack on Taiwan: Suspected Chinese hackers reportedly used open-source AI to compromise Taiwanese government systems and steal more than 2,500 personnel records. The near-autonomous operation expanded into vendors, energy, email, and nuclear safety networks, highlighting the growing risk to governments and critical infrastructure.
  2. 2 Cloud portals targeted worldwide: The City-Forum campaign is abusing permissive guest access, not software flaws, to enumerate and steal exposed data from Salesforce and ServiceNow portals. Organizations across multiple sectors should review guest permissions, sharing rules, and portal controls before quiet data exposure becomes a major breach.
  3. 3 Ransomware disrupts Canadian hospitals: An attack disabled door access and HVAC systems, forcing hospital staff to operate manually. The incident shows how ransomware can threaten physical safety and service continuity, not just patient data.

+2 more stories

Open briefing →

The rundown

  1. 1 Microsoft released patches for at least 398 vulnerabilities, including an actively exploited Windows zero-day and two publicly disclosed flaws. Security teams should prioritize the exploited issue while validating broader deployments to avoid operational disruption.
  2. 2 Russian-linked Sandworm is using fake recruitment campaigns to deliver a trojanized VPN client to system administrators and IT professionals. The operation shows how trusted tools, social engineering, and professional networks can provide access to corporate and critical infrastructure environments.
  3. 3 A nonprofit healthcare system serving Georgia and South Carolina remains disrupted two weeks after a cyberattack, with facilities still affected. A ransomware group also posted claims of stolen patient data, increasing regulatory, reputational, and patient-care pressures even though the claims remain unverified.

+2 more stories

Open briefing →

The rundown

  1. 1 Belgium’s Connective digital identity software contained critical flaws affecting more than two million users, banks and government agencies. Although fixed, the vulnerabilities could expose identity and card data, enable PIN theft and support remote compromise, threatening trust in digital government and financial services.
  2. 2 U.S. defense manufacturer IEH Corporation disclosed a phishing incident that exposed a Microsoft 365 mailbox containing customer, engineering and potentially export-controlled information. The event highlights how basic social engineering can create regulatory exposure and place defense supply chains at risk.
  3. 3 A MinterEllison report found that 71% of surveyed Australian organisations experienced a cyber incident in the past year, while average costs for large businesses rose 219% to A$202,700. AI-enabled attacks and third-party breaches are increasing pressure on boards to improve resilience, response readiness and supplier oversight.

+2 more stories

Open briefing →

The rundown

  1. 1 Alcon disclosed a breach after an unauthorized party accessed personal information linked to its systems. The incident highlights the need for stronger access controls, faster detection, and tighter protection of employee and customer data.
  2. 2 Levi Strauss said three employees were deceived by a targeted social engineering attack, allowing access to company computers and some internal files. The intrusion was contained, with no evidence of consumer-data exposure or operational disruption, but it reinforces the business impact of human manipulation.
  3. 3 Ransomware groups are increasingly targeting mid-level managers rather than CEOs, exploiting their influence over payments, contracts, budgets, and sensitive records. Zscaler identified 351 victims across 334 organizations, showing how attackers are using organizational relationships to accelerate extortion.

+2 more stories

Open briefing →

The rundown

  1. 1 A cyberattack disrupted IT systems at North Carolina’s Wilmington, Morehead City, and Charlotte Inland ports, delaying gates and affecting truck and vessel activity. The incident highlights the operational and economic impact of attacks on critical logistics infrastructure, while questions remain over possible data theft.
  2. 2 Metabase disclosed an actively exploited, critical SQL injection flaw affecting cloud and self-hosted deployments, potentially enabling administrator access. Customers are urged to patch, revoke sessions, rotate credentials, and investigate logs as reported impacts raise concerns about exposed data and connected databases.
  3. 3 Nearly 800 malicious npm packages used typo-squatting and deceptive instructions to deliver a cross-platform remote access trojan and infostealer. The campaign demonstrates how developer environments can become a pathway into enterprise networks and targeted financial operations.

+2 more stories

Open briefing →

The rundown

  1. 1 A longtime cybercriminal received a 16-year sentence for operating Ransom Cartel, which attacked at least 18 organizations and extorted $5.2 million. The case highlights the financial and operational damage that small, coordinated ransomware networks can inflict.
  2. 2 China has opened a national-security review of Palo Alto Networks products, citing critical-infrastructure protection and cyber risk. The probe could restrict the company’s access to the Chinese market and strengthen domestic competitors.
  3. 3 UNC6671, linked to the BlackFile extortion operation, targeted hedge funds and private-equity firms through helpdesk impersonation and stolen Microsoft 365 and Okta credentials. The campaign shows how social engineering can quickly escalate into cloud compromise and high-value extortion.

+2 more stories

Open briefing →

The rundown

  1. 1 A Canadian man pleaded guilty to helping breach at least 165 organizations through compromised Snowflake accounts, affecting more than 100 million people. The campaign exploited missing multi-factor authentication, stole terabytes of data, and generated multimillion-dollar extortion demands, highlighting the business cost of weak identity controls.
  2. 2 A researcher who spent 22 months inside North Korean hacking infrastructure says the activity affected 1,640 companies across 57 countries, with up to 800 suffering serious intrusions. The findings show how compromised contractors and trusted access can expose credentials, cloud environments, crypto assets, and sensitive communications worldwide.
  3. 3 Agentic ransomware and kernel-level evasion are giving attackers more autonomy while reducing defenders’ detection and response time. The trend raises significant risks for enterprises and critical infrastructure as malware becomes more adaptive and harder to contain.

+2 more stories

Open briefing →

The rundown

  1. 1 A fast-moving supply-chain attack compromised a GitHub maintainer and injected self-replicating malware into more than 860 npm packages, with over two billion monthly installs. The campaign exposed cloud, CI, AI, and cryptocurrency credentials, creating significant risk for software providers and organizations using shared dependencies.
  2. 2 A campaign targeting US water and wastewater facilities has reached at least 12 states, exploiting internet-exposed industrial controls and causing limited pressure and service disruptions. The incidents highlight critical infrastructure’s exposure and the urgent need for utilities to secure operational technology.
  3. 3 The INC ransomware group is actively exploiting two SonicWall zero-days, including after patches were released, with confirmed ransomware deployment and extortion attempts. The campaign reinforces the risk posed by perimeter devices and the need for rapid remediation, monitoring, and incident response.

+2 more stories

Open briefing →

The rundown

  1. 1 A Swiss IT agency suffered a targeted intrusion affecting around 200 user accounts, with investigators examining possible Microsoft SharePoint vulnerabilities. The incident highlights how weaknesses in collaboration platforms and stolen credentials can enable identity theft and deeper access into government and business networks.
  2. 2 Brown Health Medical Group-MA says a December 2025 incident may have exposed protected information belonging to approximately 312,000 people, including personal, financial, employment, and health-related data. Although its electronic medical record system was not affected, the breach demonstrates the lasting exposure created by legacy file servers and the need for stronger identity protection.
  3. 3 Researchers warn that email AI assistants could be manipulated through crafted messages to perform unsafe actions or disclose sensitive information. As organizations adopt tools that read and act on email, these systems may create a new pathway to account takeover and business email compromise.

+2 more stories

Open briefing →

The rundown

  1. 1 TrapDoor Supply Chain Attack: Threat actors spread credential-stealing malware via npm, PyPI, and CratesIO, exploiting open-source vulnerabilities and compromising developer environments. This highlights the urgent need for enhanced supply chain security protocols.
  2. 2 Verizon 2026 Data Breach Report: The report shows a rise in cyberattacks, especially phishing and ransomware, stressing the need for stronger cybersecurity frameworks and employee training to protect sensitive data and maintain business continuity.
  3. 3 Victorian Newspaper Ransomware Attack: A regional newspaper has been hit by a ransomware attack, disrupting operations and exposing vulnerabilities in smaller media outlets' cybersecurity, calling for improved protective measures.

+2 more stories

Open briefing →

The rundown

  1. 1 Dutch authorities have confiscated 800 servers from a Netherlands-based hosting provider known for facilitating cyberattacks. This marks a pivotal effort to dismantle the infrastructure supporting global cybercrime networks, highlighting the need for international collaboration in cybersecurity.
  2. 2 The cybercrime group Void Dokkaebi has developed a stealthy new malware called InvisibleFerret using Cython, boosting its evasion capabilities. This evolution in cyber tactics calls for more sophisticated security strategies to protect against elusive threats.
  3. 3 Grafana Labs will cease support for its open-source platform, Ghost, effective October 31, 2023, channeling focus toward primary products. This move could impact users relying on Ghost for monitoring solutions, emphasizing a shift in resource allocation within the enterprise landscape.

+3 more stories

Open briefing →

The rundown

  1. 1 Chinese hacker group Webworm exploits Discord and Microsoft Graph to breach European government networks, reflecting the increasing sophistication of attacks using legitimate platforms and urging stronger protective measures.
  2. 2 Canadian Jacob Butler, leader of the Kimwolf botnet compromising over 2 million Android devices, was arrested in Ottawa. Despite the seizure, Kimwolf's continued operation highlights persisting IoT vulnerabilities, threatening security across sectors.
  3. 3 Authorities dismantled "First VPN," a service aiding ransomware attacks by facilitating anonymity for criminals. This significant enforcement step stresses the value of global cooperation to combat cybercrime infrastructure.

+3 more stories

Open briefing →

The rundown

  1. 1 Grafana Labs' recent targeted cyberattack has exposed major vulnerabilities in supply chain dependencies, emphasizing the urgent need for stronger cybersecurity to safeguard proprietary data and open-source components.
  2. 2 In a landmark legal development, federal authorities have made the first arrests under a law against 'deepfakes' misuse in Brooklyn, underscoring the necessity of legal structures to protect against AI-driven digital misinformation.
  3. 3 The newly discovered ransomware strain, WantToCry, is exploiting SMB vulnerabilities to encrypt remote files, highlighting the critical importance of patches and cybersecurity protocols in safeguarding business data.

+2 more stories

Open briefing →

The rundown

  1. 1 GitHub finds itself under scrutiny after TeamPCP claims to have hacked its internal repositories, allegedly extracting sensitive data and demanding ransom. This breach underscores the vulnerabilities lurking in tech infrastructure, highlighting the urgent need for enhanced security measures to protect digital assets.
  2. 2 The Cybersecurity and Infrastructure Security Agency (CISA) faces backlash following the accidental exposure of sensitive credential data on GitHub. This significant leak has prompted demands for a thorough investigation into CISA’s internal security practices, especially as the U.S. grapples with heightened cybersecurity threats.
  3. 3 Stay tuned to Hacked dAily for insightful analysis and the latest developments in cybersecurity tailored for leaders who need to stay one step ahead.
Open briefing →

The rundown

  1. 1 Today's top story highlights INTERPOL's Operation Ramz, which arrested 201 individuals in a massive MENA region crackdown on cybercrime, demonstrating the critical importance and success of international cooperation in disrupting phishing scams and malware networks.
  2. 2 Next, security researchers unveil GhostTree, a path manipulation technique that bypasses Windows defenses, emphasizing an urgent need for updating enterprise security measures to counteract potential unauthorized access exploits.
  3. 3 Verizon's Data Breach Investigations Report shows exploited vulnerabilities now account for 31% of breaches, up from 20%, with a concerning gap in handling critical vulnerabilities, while ransomware tactics evolve with fewer victims choosing to pay attackers.

+2 more stories

Open briefing →

The rundown

  1. 1 A security flaw in the Funnel Builder WooCommerce plugin is actively exploited for checkout skimming, compromising customer payment data and underscoring the urgency of regular updates to e-commerce platforms.
  2. 2 Grafana Labs reported a breach involving the theft of source code but refused to pay ransom, highlighting the critical need to strengthen intellectual property protection and cybersecurity strategies.
  3. 3 OtterCookie, a new JavaScript and Node.js tool, has evolved from credential theft to active surveillance, delivered via npm and Vercel, posing significant data privacy risks.

+2 more stories

Open briefing →

The rundown

  1. 1 A deep dive into a vishing extortion operation uncovers cybercriminals adeptly exploiting phone-based fraud to trick victims and steal sensitive information. This emphasizes the need for upgraded vigilance and effective employee training against sophisticated voice-based threats.
  2. 2 The Fragnesia vulnerability (CVE-2026-46300) in Linux systems is a severe security risk, enabling unauthorized root access across multiple distributions. Organizations must urgently reassess protocols and deploy patches to protect critical systems and data.
  3. 3 PoC code for a critical NGINX vulnerability has been released, risking widespread code execution exploits. With NGINX's vast usage, swift system updates are crucial to maintaining security and operational integrity globally.

+3 more stories

Open briefing →

The rundown

  1. 1 Microsoft is boosting system security by automatically rolling back faulty Windows drivers, minimizing vulnerabilities and ensuring operational stability for users and enterprises.
  2. 2 VELVET CHOLLIMA, a new malware threat employing a fake trading app, emphasizes the rising complexity of cyberattacks, urging increased cybersecurity vigilance in the trading sector.
  3. 3 On Pwn2Own Berlin 2026's first day, experts unveiled 24 zero-day vulnerabilities, focusing on AI products and awarding $523,000 in bounties, showcasing the critical role of such events in preemptive cyber defense.

+3 more stories

Open briefing →

The rundown

  1. 1 Our top story reveals new zero-day vulnerabilities, YellowKey and GreenPlasma, in Windows OS, enabling potential code execution and privilege escalation. This discovery emphasizes the urgent need for rapid patches and vigilant system defenses.
  2. 2 In financial tech news, Abrigo suffered a breach affecting over 711,000 accounts, highlighting the increasing threats in fintech. Financial institutions must take proactive steps to fortify their cybersecurity frameworks to protect sensitive client data.
  3. 3 A cyber campaign, VELVET CHOLLIMA, uses a trading app as bait to deploy infostealer malware, showcasing sophisticated tactics by cybercriminals. Organizations are urged to rigorously vet apps and enhance security postures against such ploys.

+3 more stories

Open briefing →

The rundown

  1. 1 Texas Attorney General Ken Paxton has sued Netflix for allegedly collecting and selling user data without consent, potentially reshaping data privacy standards across streaming services and affecting Netflix's targeted advertising strategies, especially for minors.
  2. 2 Instructure settled with the ShinyHunters group following a breach that compromised educational data, prompting scrutiny by the U.S. House Committee on Homeland Security and raising concerns about data security in educational tech.
  3. 3 Ukraine's security officials linked a cyber-espionage operation to Russia's Gamaredon group, underscoring the need for heightened cyber defenses against evolving state-sponsored threats in geopolitical conflicts.

+3 more stories

Open briefing →

The rundown

  1. 1 Analysts have exposed a new CRPx0 malware vector targeting users with fake OnlyFans offers. This technique highlights the evolving threat landscape, emphasizing the need for robust security strategies to protect sensitive data.
  2. 2 The Nitrogen ransomware group targeted Foxconn, claiming 8 terabytes of data from their Wisconsin plant. This spotlight on data security urges corporations to enhance protective measures against breaches.
  3. 3 A supply chain attack hit TanStack, Mistral AI, and UiPath, revealing vulnerabilities in tech vendor ecosystems. Companies must reassess supply chain security to combat growing third-party risks.

+2 more stories

Open briefing →

The rundown

  1. 1 A newly found Linux flaw, tagged "Dirty Frag," poses significant risks to enterprise systems due to its potential to let attackers bypass security through fragmented IP packets. Organizations must urgently examine their defenses against this emerging threat.
  2. 2 Skoda Auto's online shop suffered a data breach exposing personal customer data, emphasizing the critical need for robust cybersecurity as automakers extend their digital services.
  3. 3 BWH Hotels faced a data breach compromising six months of personal and reservation details, reflecting the vulnerabilities in third-party managed systems and the necessity for stringent safeguards in handling sensitive data.

+3 more stories

Open briefing →

The rundown

  1. 1 Hackers are leveraging Google ads and Claude.ai chats to spread macOS malware, raising urgency for improved ad security and vetting for safer user interactions.
  2. 2 Cybercriminals manipulated DigiCert to obtain legitimate digital certificates, using them to legitimize malware and evade detection, stressing the need for stronger certificate validation protocols.
  3. 3 The shutdown of the Crimenetwork marketplace following the arrest of its administrator marks a key victory in combatting cybercrime, disrupting illicit trade and curtailing data theft operations.

+3 more stories

Open briefing →
Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.