Skip to content
Hacked dAily
All Episodes

Hacked dAily Episodes

Every episode of Hacked dAily: 500 daily cybersecurity briefings and counting. Breaking news on breaches, ransomware and AI threats. Page 4 of 21.

The rundown

  1. 1 Today, we delve into a sophisticated supply-chain attack by UNC6426 on the nx npm package, exploiting software dependencies to gain AWS administrator access. This highlights urgent security gaps in the cloud infrastructure, demanding stronger measures in software supply chains.
  2. 2 In Europe, a legal advisor suggests banks should prioritize reimbursing cybercrime victims before claim legitimacy assessments. This could reshape financial institutions' approach to cyber incidents, enhancing consumer trust and accelerating relief.
  3. 3 Five malicious Rust crates have surfaced, exploiting CI/CD pipelines with AI bots to steal developer secrets. This emphasizes the need for securing development pipelines as attackers increasingly target automated systems, risking widespread breaches.

+3 more stories

Open briefing →

The rundown

  1. 1 First, MyFitnessPal, now under Cal AI, has endured a significant data breach affecting 3 million users, exposing personal information and highlighting persistent vulnerabilities in health apps. This breach underscores the urgency of robust security measures in our digitized world.
  2. 2 Next, telecom giant Ericsson has suffered a breach jeopardizing 15,000 employees and customers' sensitive data. This incident stresses the need for stringent cybersecurity protocols in critical industry sectors.
  3. 3 Introducing the 'BlackSanta' malware targeting HR departments, which cleverly sidesteps EDR systems. This tactic underlines the necessity for revised security measures and awareness training within organizations to counter such sophisticated threats.

+3 more stories

Open briefing →

The rundown

  1. 1 Today, ShinyHunters have breached Salesforce customer data, spotlighting vulnerabilities in cloud services and urging enterprises to enhance cybersecurity measures. Meanwhile, Hackerbot-Claw's attack on GitHub repositories, including those of Microsoft, emphasizes the growing threat posed by AI-driven cyber incidents and the need for strengthened digital defenses.
  2. 2 In Asia, web server vulnerabilities have been exploited to target critical infrastructure, using the Mimikatz tool, highlighting the need for robust protection to prevent national security and public safety disruptions. First Priority Group, a key U.S. emergency vehicle manufacturer, faces severe risks after a ransomware attack by Everest group, exposing sensitive operational data and posing challenges in law enforcement and public safety domains.
  3. 3 Finally, new research on AI security reveals vulnerabilities beyond traditional threats, as attackers leverage trial accounts to deploy malicious AI models. This exposure pushes organizations to reassess AI and cloud security strategies, focusing on protective measures to safeguard against internal breaches.

+1 more story

Open briefing →

The rundown

  1. 1 The White House has unveiled President Trump's Cyber Strategy, focusing on deterring cyber adversaries and fortifying national cybersecurity. This transformative approach is crucial for safeguarding U.S. economic stability and national security against growing cyber threats.
  2. 2 A critical vulnerability in Context7 MCP server poses risks of unauthorized data manipulation via AI assistants. This flaw underscores the urgency for securing AI infrastructures as dependency on artificial intelligence expands across sectors.
  3. 3 The emergence of INC's ransomware affiliate model allows cybercriminals to enhance campaign reach and efficacy, raising alarms among cybersecurity experts. This evolution in ransomware tactics necessitates robust defensive strategies to protect critical infrastructure.

+2 more stories

Open briefing →

The rundown

  1. 1 Anthropic's AI model Claude Opus 4.6 has identified 22 vulnerabilities in Firefox, highlighting gaps exploitable by malicious actors. This underscores AI's critical role in preemptively identifying threats, necessitating swift action to safeguard user data.
  2. 2 Cognizant's TriZetto Provider Solutions disclosed a breach affecting over 3.4 million patients, exposing gaps in healthcare cybersecurity and posing significant risks of identity theft. The breach, unnoticed for over a year, calls for improved network monitoring.
  3. 3 The case of Daniel Rigmaiden reveals the FBI's use of Stingray surveillance without warrants, fueling debates on privacy and legality. This underlines the need for transparency and legal frameworks governing law enforcement technologies.

+3 more stories

Open briefing →

The rundown

  1. 1 First up, Wikipedia was hit by a JavaScript worm, leading to widespread vandalism. This breach exposes vulnerabilities in user-generated platforms and urges reinforced security in content management systems to prevent similar threats.
  2. 2 Next, the FBI tackled suspicious network activities linked to surveillance systems. Although details are sparse, the event highlights enduring security challenges amid budget restrictions and staffing issues, stressing the need for resilient cybersecurity strategies within governmental entities.
  3. 3 Bing AI mistakenly promoted a fake OpenClaw GitHub repository housing info-stealing malware. This incident underscores the crucial need for enhanced vetting in AI search engines to avert the spread of malicious content and safeguard user security.

+3 more stories

Open briefing →

The rundown

  1. 1 GCHQ's discussions on a cyber threat firewall raise privacy debates and concerns over a potential VPN ban, with efforts focusing on children's online protection rather than adult restrictions, acknowledging the broad economic impact of comprehensive VPN prohibitions.
  2. 2 Telegram's rise as a cybercrime marketplace, fueled by encryption and anonymity, amplifies cybersecurity threats. This trend demands enhanced monitoring and measures against illicit activities affecting sensitive data spread.
  3. 3 Silver Dragon, linked to APT41, is targeting government entities using sophisticated tactics like Cobalt Strike payloads and Google Drive for command control. This highlights the national security risks and the imperative for heightened vigilance by government cybersecurity teams.

+3 more stories

Open briefing →

The rundown

  1. 1 Facebook users worldwide experience a major outage, blocking access and disrupting Meta's business services like Ads Manager and WhatsApp Business API. This highlights vulnerability in global connectivity and business operations, with no link to country-level internet issues confirmed.
  2. 2 In France, cybercriminals breach the Ministry of Health, stealing 15.8 million medical records. This breach underscores the need for robust cybersecurity to protect sensitive healthcare data and maintain trust in public institutions.
  3. 3 Drone attacks on AWS data centers in the Middle East reveal vulnerabilities in critical infrastructure. This raises security concerns, stressing the importance of securing digital operations in conflict-prone areas, given AWS's critical role for global enterprises.

+3 more stories

Open briefing →

The rundown

  1. 1 ShinyHunters breaches Dutch telecom Odido, leaking over 15 million records. The breach highlights vulnerabilities in safeguarding sensitive customer data, emphasizing the urgent need for robust cybersecurity against organized cybercrime.
  2. 2 Microsoft alerts users to a Remote Access Trojan hidden in compromised gaming utilities. These deceptive tactics stress the importance of vigilance and robust cybersecurity to protect individuals and organizations from unauthorized system access.
  3. 3 A Senate panel pushes forward legislation to bolster healthcare cybersecurity, addressing mounting threats to patient data and hospital operations. This initiative underscores the critical role of enhanced cybersecurity in protecting national health infrastructure.

+3 more stories

Open briefing →

The rundown

  1. 1 Today's top story: Europol's international crackdown has dismantled The Com cybercrime network, leading to 30 arrests. This highlights global law enforcement collaboration as crucial to protecting digital infrastructures from sophisticated threats impacting businesses and economies.
  2. 2 Researchers at Qrator Labs discovered the Aeternum botnet, which uses smart contracts on the Polygon blockchain for command-and-control. Its decentralized structure poses new challenges for cybersecurity, signaling a shift in how malware operators maintain resilience against takedowns.
  3. 3 The "ClawJacked Flaw" allows malicious websites to hijack OpenClaw AI agents through WebSocket connections, risking sensitive data and operational integrity. This reveals the ongoing need for robust web communication security in AI environments.

+3 more stories

Open briefing →

The rundown

  1. 1 Former President Trump has mandated the phase-out of Anthropic technology across federal agencies, citing national security concerns. This move highlights the critical need for balancing innovation with data protection in governmental systems.
  2. 2 Google reports threat actors are embedding AI into cyber attacks, with countries like China and Russia leading aggressive strategies. This evolution in tactics calls for enhanced protection of AI models, reshaping both offensive and defensive cyber landscapes.
  3. 3 Apple's iPhone and iPad have received NATO clearance for classified communications, marking a major milestone for consumer devices in defense applications. This demonstrates Apple's strong security protocols aligning with stringent military standards.

+2 more stories

Open briefing →

The rundown

  1. 1 Top Story 1: Global cybersecurity agencies urge immediate patching of a zero-day flaw in Cisco's SD-WAN software, allowing unauthorized access. Cisco's patch is crucial as enterprise networks face significant risks. Swift action is essential to safeguard sensitive data and operational integrity.
  2. 2 Top Story 2: DevChallenges.io suffers a breach, exposing sensitive user data on a hacking forum. The exposed information raises privacy concerns for developers and stresses the persistent risks of data exposure in online platforms.
  3. 3 Top Story 3: UAT-10027, a threat campaign, targets U.S. education and healthcare sectors using a backdoor called Dohdoor, hijacking HTTPS connections. Linked to North Korea's Lazarus Group, this underscores global cyber threat evolution and the need for advanced defenses.

+2 more stories

Open briefing →

The rundown

  1. 1 ShinyHunters has leaked data from 12.4 million CarGurus accounts after a failed extortion attempt, exposing users to phishing and identity theft risks. This incident highlights the importance of strong cybersecurity measures to protect consumer trust.
  2. 2 SolarWinds has issued patches for four critical vulnerabilities in its Serv-U software. Immediate application is crucial to prevent unauthorized access and maintain data integrity across enterprise environments.
  3. 3 Wynn Resorts has trusted attacker assurances that stolen employee data is deleted, raising concerns over corporate negotiation tactics and data security strategies. This case emphasizes the need for comprehensive cybersecurity response plans.

+3 more stories

Open briefing →

The rundown

  1. 1 Today, we explore the recent ransomware attack on the Transport Workers Union of America Local 100 by the Qilin group. This breach compromised sensitive member data, highlighting how labor organizations become prime cybercriminal targets due to their inadequate defenses.
  2. 2 Next, RCA, a major medical billing firm, faces a significant data breach, claimed by two ransomware groups. The incident emphasizes the crucial need for stronger data protection in healthcare, as sensitive data remains a lucrative target.
  3. 3 We delve into the short-lived ascent and decline of Arkanix Stealer, an AI-assisted malware that pilfered sensitive data like browser credentials and cryptocurrency wallets. Though now defunct, its rapid emergence signals shifts towards experimental cyber campaigns.

+3 more stories

Open briefing →

The rundown

  1. 1 Top Story 1: Apriora Inc., known as Alex AI, suffered a data breach exposing 784,000 candidate records and critical API credentials for platforms like Salesforce. This incident highlights privacy risks in recruiting tech, demanding upgraded cybersecurity protocols.
  2. 2 Top Story 2: A YouX ransomware attack exposed 230,000 Australian driver licenses and personal data of over 444,000 individuals. The breach underscores vulnerabilities in automotive finance cybersecurity, necessitating improved protections and swift regulatory responses.
  3. 3 Top Story 3: Chinese hackers breached Italy's Ministry of the Interior, affecting identities of 5,000 Digos agents, crucial in organized crime investigations. This raises national security concerns, emphasizing the need for robust government cybersecurity measures.

+2 more stories

Open briefing →

The rundown

  1. 1 Our top story features Anthropic's launch of Claude Code Security, an AI-powered tool that scans software for vulnerabilities. With its human-like code analysis, this tool promises precise detection and minimized false positives, marking a strategic advance against AI-driven cyber threats.
  2. 2 In ransomware news, threat actors exploit virtual machine templates to expedite attacks and evade defenses. This trend necessitates heightened vigilance over virtual environments to prevent widespread data encryption.
  3. 3 We also discuss the compromise of the Cline CLI npm package, where malicious code led to the distribution of the OpenClaw tool. This breach highlights the urgent need for robust security measures in managing software supply chains.

+3 more stories

Open briefing →

The rundown

  1. 1 A critical vulnerability in BeyondTrust Remote Support has been exploited by ransomware gangs, threatening enterprises dependent on this software for remote operations. This incident underscores the need for robust patch management and fortified cybersecurity defenses.
  2. 2 Bumble faces a class action lawsuit following a significant data breach exposing user information. This legal action spotlights the imperative for stringent security measures to protect user data and maintain trust in the online dating sphere.
  3. 3 Researchers have identified malicious Facebook ads distributing fake Windows 11 downloads aimed at stealing users' credentials and cryptocurrency. This campaign exemplifies the sophistication of cyber attacks using popular platforms, urging businesses and individuals to enhance preventive measures.

+2 more stories

Open briefing →

The rundown

  1. 1 First, a major data breach at Banque de France's bank registry service has exposed the personal information of 1.2 million accounts. This incident is a stark reminder for banks to strengthen their cybersecurity protocols to maintain trust and comply with regulations.
  2. 2 Next, the 'Starkiller' phishing kit, capable of bypassing multi-factor authentication, poses new risks for organizations. Its emergence warns businesses about the need to continually enhance their security frameworks to fend off sophisticated threats.
  3. 3 Meanwhile, a newly identified Android malware exploits Google Gemini's AI capabilities to evade detection, threatening the security of millions of Android users. This highlights the imperative for robust security measures to confront advanced malware tactics.

+3 more stories

Open briefing →

The rundown

  1. 1 Top Story 1: DEF CON bans three men allegedly linked to Jeffrey Epstein from future events, reflecting its stand on ensuring a secure, ethical space against potential compromise of trust and integrity in the tech community.
  2. 2 Top Story 2: A surge in vishing attacks targets Microsoft Entra, manipulating user trust to access critical networks, stressing the necessity for heightened vigilance and robust security frameworks as businesses expand their cloud-based operations.
  3. 3 Top Story 3: RTL Group investigates a potential breach affecting over 27,000 employees' data, with implications for data privacy and organizational security in the entertainment sector amid cybercrime forum claims of extensive data theft.

+3 more stories

Open briefing →

The rundown

  1. 1 Dutch police erroneously sent confidential files to an individual who was then arrested for "hacking." This raises alarms about data management and the need for strict protocols in law enforcement agencies to safeguard private information.
  2. 2 A new phishing scam mimicking Google Forms is misleading users into submitting Google logins via fake URLs. The campaign targets individuals with job offers, stressing the need for vigilance and cybersecurity tools to counteract such threats.
  3. 3 Deutsche Bahn recovered from a DDoS attack that impacted train services, attributed to pro-Russian hackers. This highlights vulnerabilities in critical infrastructure and the essential need for enhanced digital resilience to protect public systems.

+3 more stories

Open briefing →

The rundown

  1. 1 Microsoft has identified a vulnerability where "Summarize with AI" prompts could be manipulated in chatbots, potentially impacting decision-making by misleading users. This discovery highlights the importance of safeguarding AI systems to maintain trust and accuracy.
  2. 2 A sophisticated spam operation is exploiting Atlassian Jira to target organizations by embedding harmful links in legitimate notifications, risking data breaches. This campaign stresses the need for robust security measures for platforms trusted by enterprises.
  3. 3 Spain's legal authorities have required NordVPN and ProtonVPN to block websites linked to the piracy of LaLiga broadcasts, aimed at defending legitimate content distribution and tackling significant revenue losses from illegal streaming.

+3 more stories

Open briefing →

The rundown

  1. 1 In today's episode, we explore Google's findings on state-sponsored hackers from China, Russia, Iran, and North Korea leveraging AI, specifically targeting Google's Gemini. This marks a concerning leap in APT capabilities, emphasizing the need for fortified defenses against AI-enhanced attacks.
  2. 2 DavaIndia Pharmacy's data breach reveals significant vulnerabilities in their online platform, risking customer data privacy and compliance. This incident signals an urgent call for enhanced security measures in healthcare and pharmaceuticals.
  3. 3 A recent study uncovers 25 distinct attacks on major cloud password managers, exploiting flaws in password recovery systems. This revelation urges an industry-wide reassessment of password security protocols to safeguard information.

+3 more stories

Open briefing →

The rundown

  1. 1 Today, Google responds to the first actively exploited zero-day vulnerability in Chrome for 2026 by releasing a vital security update, emphasizing the importance of keeping software current to protect against data threats.
  2. 2 LockBit 5.0 emerges with enhanced cross-platform ransomware capabilities, impacting Windows, Linux, and VMware's ESXi systems. This development stresses the need for robust security across all platforms to counteract growing ransomware threats.
  3. 3 CISA adds vulnerabilities from SolarWinds, Microsoft, Apple, and Notepad++ to its Known Exploited Vulnerabilities catalog, urging federal and private sectors to prioritize fixes and bolster defenses amidst a rising threat landscape.

+3 more stories

Open briefing →
Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.