Skip to content
Hacked dAily
All Episodes

Hacked dAily Episodes

Every episode of Hacked dAily: 500 daily cybersecurity briefings and counting. Breaking news on breaches, ransomware and AI threats. Page 5 of 21.

The rundown

  1. 1 A staggering 287 Chrome extensions have been caught secretly harvesting data from 37 million users. This revelation demands immediate action from browser developers to strengthen privacy controls and underscores the critical need for user vigilance against hidden data collection.
  2. 2 An SEO poisoning campaign by BADIIS is manipulating search results to spread malware globally. This attack necessitates a strategic overhaul of digital security measures, spotlighting the innovative tactics used by cybercriminals to exploit everyday online activities.
  3. 3 Fintech firm Figure has suffered a data breach due to a phishing attack, exposing sensitive customer data. This breach highlights the growing threat of phishing and the essential need for robust employee training and cybersecurity protocols to safeguard financial institutions.

+3 more stories

Open briefing →

The rundown

  1. 1 Artificial intelligence is empowering cybercriminals, enhancing the speed and sophistication of their attacks on U.S. sectors like healthcare and finance. This evolution demands AI-driven defenses to maintain resilience.
  2. 2 CISA warns of active vulnerability exploitation in SolarWinds, Notepad++, and Microsoft products, stressing the importance of immediate patches to protect data and maintain security integrity.
  3. 3 Luxury brands Louis Vuitton, Dior, and Tiffany face a $25 million fine after customer data breaches, prompting increased regulatory oversight and the need for stronger data protection to safeguard customer trust.

+3 more stories

Open briefing →

The rundown

  1. 1 The podcast begins with a significant data breach at Dutch telecom firm Odido, exposing personal details of 6.2 million customer accounts. While passwords remain secure, customers are urged to remain vigilant, highlighting the urgent need for enhanced security measures.
  2. 2 McLaren Health's $14 million settlement following ransomware attacks emphasizes the costly risks of cybersecurity lapses in healthcare, with growing accountability for safeguarding patient data amid rising threats.
  3. 3 The World Leaks ransomware group has introduced 'RustyRocket,' a stealthy malware developed in Rust, posing a detection challenge. This evolution in tactics demands urgent updates in cybersecurity strategies globally.

+3 more stories

Open briefing →

The rundown

  1. 1 In Paris, a ransomware trial against a couple reveals the pervasive nature of modern cybercrime, emphasizing the necessity of heightened cybersecurity to protect financial stability and data integrity.
  2. 2 A new threat actor, UAT-9921, utilizes the advanced VoidLink framework to execute stealth attacks, underscoring the urgent need for robust defenses against evolving threats.
  3. 3 The Cl0p ransomware group has breached 25 global organizations, targeting diverse sectors from healthcare to investment, underscoring the profound threat ransomware poses to operational integrity and data security.

+1 more story

Open briefing →

The rundown

  1. 1 Today's top story involves the Birmingham Mental Health Authority in Alabama, alerting over 30,000 individuals of a potential data breach linked to Medusa's ransomware, underscoring the ongoing vulnerabilities in healthcare systems and potential risks to patient privacy and safety.
  2. 2 In another blow to healthcare security, the networking platform Sermo was hit by ransomware, risking exposure of millions of medical professionals' sensitive data. This attack highlights the urgency for enhanced cybersecurity practices across healthcare-related networks.
  3. 3 Kyle Svara has confessed to hacking hundreds of Snapchat accounts using social engineering. This case, involving identity theft and computer fraud, stresses the need for stronger social media platform security measures against such deceptive hacking tactics.

+3 more stories

Open briefing →

The rundown

  1. 1 In today's episode:
  2. 2 Social media platforms are reportedly profiting from fake and scam ads, threatening consumer protection and digital trust. Impersonating legitimate brands, they trick users into divulging personal data, emphasizing the need for stricter regulations and enhanced oversight.
  3. 3 The European Commission swiftly contained a cyber-attack targeting its staff mobile data management infrastructure, preventing extensive damage. This incident highlights the Commission's strong response strategy, bolstered by Cybersecurity Act 2.0, reinforcing EU-wide defenses.

+4 more stories

Open briefing →

The rundown

  1. 1 South Korean crypto exchange Bithumb erroneously transferred 620,000 Bitcoin, valued at $40 billion, to users' accounts, igniting concerns over operational controls. This highlights the urgent need for robust system checks and regulatory oversight to safeguard investor confidence.
  2. 2 A UK construction firm fell prey to the Prometei botnet, exploiting Windows Server vulnerabilities for cryptojacking. This highlights the escalating threat of advanced persistent threats, emphasizing the critical need for stringent cybersecurity measures and constant vigilance.
  3. 3 OpenClaw has integrated VirusTotal scanning to enhance ClawHub Skills security, demonstrating its commitment to user protection against cyber threats. This integration fortifies the platform's defenses, maintaining user trust in its cybersecurity capabilities.

+2 more stories

Open briefing →

The rundown

  1. 1 The Nitrogen ransomware group faces a self-inflicted setback as a key management flaw locks them out of their own payment systems, leaving victims' data irretrievable. This highlights a critical vulnerability in ransomware infrastructure and underscores broader risks of data loss.
  2. 2 Conduent faces a data breach compromising over 25 million individuals' sensitive information. The incident reinforces the necessity for robust cybersecurity measures amid sophisticated cyber threats, stressing potential global repercussions for stakeholders.
  3. 3 La Sapienza University in Rome grapples with a cyber attack, disrupting its digital infrastructure and key resources for students and faculty. This incident highlights the ongoing threat to educational institutions and the importance of protecting sensitive data.

+2 more stories

Open briefing →

The rundown

  1. 1 Flickr has reported a potential data breach affecting some of its 35 million monthly users, linked to a third-party email service vulnerability. While no passwords or payment data were leaked, exposed usernames, email addresses, and IP addresses heighten phishing risks, prompting enhanced vendor security protocols.
  2. 2 The Payouts Kings ransomware group claims to have attacked Prater Engineering Associates, Inc., threatening to release 2.5 terabytes of sensitive data within six days. This underscores vulnerabilities in the engineering sector, demanding rigorous cybersecurity defenses.
  3. 3 Germany warns of hackers targeting Signal accounts, particularly those of senior governmental and corporate figures, using SIM-swapping tactics. This calls for urgent enhancements in securing high-level communications channels.

+3 more stories

Open briefing →

The rundown

  1. 1 ShinyHunters, linked to the LAPSUS$ collective, breached Harvard's Alumni Affairs, leaking 115,000 donor records, including data from Mark Zuckerberg and Michael Bloomberg, stressing the need for stronger cybersecurity in educational institutions.
  2. 2 Epworth HealthCare denies data breach claims despite ransomware attackers alleging theft of 920GB of sensitive data, emphasizing the need for ongoing vigilance in healthcare cybersecurity.
  3. 3 A new variant of the ClickFix campaign, named "CrashFix," utilizes a Python RAT and browser crashes, highlighting the evolving tactics of cybercriminals and underscoring the necessity for behavior-based detection strategies.

+3 more stories

Open briefing →

The rundown

  1. 1 Hackers have exploited a critical vulnerability in React Native's Metro bundler, breaching developer systems and allowing unauthorized code execution. This emphasizes the urgent need for developers to apply patches to secure their environments and highlights the importance of robust cybersecurity practices.
  2. 2 ShadowSyndicate has significantly expanded its infrastructure, showcasing its adaptability and increasing the global threat landscape. Organizations must strengthen defenses as this expansion could heighten risks to sensitive data and critical systems.
  3. 3 A tool dubbed the "EDR killer" exploits a signed kernel driver to bypass EDR systems, posing severe risks to enterprise cybersecurity. This development stresses the necessity for enhanced scrutiny of third-party drivers and adapting security strategies.

+3 more stories

Open briefing →

The rundown

  1. 1 French authorities raided the Paris HQ of Elon Musk's X over algorithmic manipulation and illicit content, spotlighting AI-generated illegal content concerns. This probe may escalate into international scrutiny and lead to potential EU fines or restrictions.
  2. 2 Chinese state-sponsored hackers have reportedly compromised Notepad++'s update mechanism to distribute malware, showcasing sophisticated exploitation of legitimate processes. This breach calls for stronger software supply chain security to prevent global data breaches.
  3. 3 A privacy breach in Bondu's AI toys exposed 50,000 child conversations. Though swiftly addressed, this incident emphasizes the need for stringent privacy and security measures in AI-powered children's products.

+2 more stories

Open briefing →

The rundown

  1. 1 Spotify and major music labels have filed a $13 trillion lawsuit against Anna’s Archive, accusing it of distributing copyrighted music without permission. This case exemplifies the clash between digital piracy and copyright enforcement, with severe financial and legal stakes at play.
  2. 2 Hackers breached StopICE, an immigrant rights group's communication system, sending alarming texts allegedly linked to a border patrol agent. This breach raises concerns about activist groups' digital security and highlights tensions with government agencies.
  3. 3 ShinyHunters-branded groups are conducting vishing campaigns against cloud SaaS platforms, targeting Microsoft 365 and Salesforce credentials. These attacks spotlight the importance of robust identity protections as attackers bypass traditional security to access valuable business data.

+2 more stories

Open briefing →

The rundown

  1. 1 Over at Marquis Software, we ponder whose bright idea it was to let SonicWall join the hackers' hall of fame, proving that sometimes the internet's friendly neighborhood developer is actually a wolf in firewall's clothing.
  2. 2 In a dramatic twist out of a cyber-thriller, FBI files unveil Jeffrey Epstein had his very own digital enigma, a hacker specializing in zero-day exploits, and no, he wasn't just the guy fixing your PC. It's a mystery layered in intrigue, a cyber-sleuth's dream drama.
  3. 3 Meanwhile, as Tulsa International Airport dodges digital disasters, their IT department seems to have packed all the right gear to fight ransomware turbulence. They've got cyber turbulence under control, or so they claim.

+1 more story

Open briefing →

The rundown

  1. 1 First up, our researcher discovered Instagram's private profiles are as secure as wearing flip-flops in a snowstorm, hint: they're not. If you thought your pet selfies were exclusive to followers, think again.
  2. 2 Next, the FBI dismantled the RAMP ransomware forum, sending nefarious actors scrambling like cockroaches under a spotlight. A quick chuckle for cybersecurity professionals, knowing even the bad guys need protection from each other.
  3. 3 Over at Panera Bread, they've baked more than bread: a data breach affecting over 5 million customers. This isn't sourdough, but it sure has left a sour taste. Pass the securely-encrypted baguette, please!

+2 more stories

Open briefing →

The rundown

  1. 1 Meanwhile, the notorious Labyrinth Chollima hacking collective has decided one group wasn't enough. They've split into three, offering the global cybersecurity world a complimentary migraine. Think of it as a 'Buy One Get Two Free' special from the world of cybercrime.
  2. 2 Speaking of mischief, 0APT ransomware group is scattering data across their leak site like it's Black Friday, grabbing 60 new victims in a day. And for dessert, Sonnet 4.5 AI gives a master class in replicating history's nastiest breaches, proving once again that your best security move might just be befriending the IT department.
Open briefing →

The rundown

  1. 1 First up, Louis Vuitton learned that a sequined handbag can't patch up a data breach. Salesforce warned them, but who needs emails when you're neck-deep in high fashion? Pro tip, Always accessorize with a cybersecurity alert!
  2. 2 Next, Match Group exposed more than just your dating profile. Hinge, Tinder, and OkCupid roll out your personal data like Valentine's Day popcorn. Note: Secure the match, and maybe, your heart.
  3. 3 Meanwhile, across the pond, EU data breach notifications spiked 22%. GDPR fines still lounging at EUR1.2 billion, with Ireland's Data Protection Commission handing TikTok a EUR530 million bill. Who knew dance moves came with such a hefty price tag?

+2 more stories

Open briefing →

The rundown

  1. 1 First up, let's talk about n8n. Remember the software that vowed to streamline our lives? Turns out, it accidentally handed cybercriminals the keys to the kingdom by unveiling two critical vulnerabilities. We could say they "automagically" created chaos instead of calm, oopsie!
  2. 2 Next, we dive into the cybercrime escapades of the not-so-imperial owner of the Empire Market. This cyber "czar" has admitted to a rather narcotic conspiracy. Yep, it appears his technologically-savvy fortress crumbled faster than a house of cards.
  3. 3 Meanwhile, over at PyPI, cyber tricksters smuggled in Remote Access Trojans disguised as spellcheckers. It's Shakespearean irony at its finest, a spellchecker that spells trouble! Who said coding editors couldn’t be thrilling?

+3 more stories

Open briefing →

The rundown

  1. 1 In today's lineup: SoundCloud has become more of a public jam session as 29.8 million user accounts face exposure, making your guilty pleasure playlist a potential public broadcast. Maybe it's time to reconsider that Justin Bieber phase!
  2. 2 Meanwhile, the U.S. government indicts 31 tech-savvy individuals in a scandalous round of ATM malware attacks. Forget swiping cards; these folks are hacking cash like it's a competitive sport.
  3. 3 Over in the healthcare realm, zHealthEHR is stuck in a spine-rattling drama after a cyber thief claims to have swiped 1.2 million patient records. Don’t worry, they're only asking half a million dollars, who knew medical data could become a hot commodity?

+3 more stories

Open briefing →

The rundown

  1. 1 Today, we delve into X, the platform formerly known as Twitter. The EU's got them under the spotlight for their Grok AI producing steamy sketches when it should be doodling happy little trees. Looks like X's artistic endeavors are painting them into a scandalous corner!
  2. 2 Meanwhile, Okta’s latest revelation has all of us questioning if MFA is just a high-tech paperweight. Turns out, hackers are tailoring voice phishing scams like they’re auditioning for a cyber heist reality show.
  3. 3 In other nerve-racking news, the University of Hawai'i Cancer Center found itself ransomware's latest victim. Patient data, swiped faster than a postcard in a souvenir shop, who knew research was such hot property?

+2 more stories

Open briefing →

The rundown

  1. 1 In today's episode, good news for forgetful folks: 149 million login details have popped up online. A kinder hacker might just call it a freebie password manager, but alas, identity theft enthusiasts are having quite the field day with it instead.
  2. 2 We also explore the tech villain TrueSightKiller. No, it's not a new Marvel character but a cyber weapon dismantling EDR systems with the finesse that puts most IT departments to shame. It's like your computer's got a case of the Mondays, courtesy of code-savvy troublemakers.
  3. 3 And in a world that says "Why sleep when you can panic?" PDFSIDER malware glides effortlessly past antivirus defenses using DLL side-loading. Fantastic if you enjoy drinking coffee by the gallon while some hacker twirls your security around their pinkie.

+3 more stories

Open briefing →

The rundown

  1. 1 First up, millions of Gmail and Facebook credentials have unintentionally found their way online. Yes, the tech giants are apparently competing in a "Share Your Data" contest, and, spoiler alert, we're all on the losing side. If you thought your password was safe, it may now double as a public Wi-Fi password!
  2. 2 Meanwhile, Microsoft decided it'd be fun to hand BitLocker recovery keys to the FBI. Who needs doorbells when you can have surprise guests at your digital doorstep courtesy of surveillance?
  3. 3 Over in Europe, the GCVE is having a meltdown over fragmented vulnerability databases. Managing this chaos is like expecting synchronized swimming from a herd of cats, fun in theory, pandemonium in practice.

+3 more stories

Open briefing →

The rundown

  1. 1 First up, Nike is trading running tracks for ransomware traps. Instead of cheering "just do it," hackers have locked up systems faster than Usain Bolt in a 100-meter dash. Let's see if Nike can sprint past this data breach to triumph, or if their cybersecurity endurance needs some training.
  2. 2 Next, New Zealand’s Manage My Health platform delivers an unintended health scare – thanks to a data breach. Users now have the chance to shine with a "No Impact" badge, even if the hackers remain unimpressed with this new feature of self-congratulatory banners.
  3. 3 Meanwhile, Lovsuit.com, France's digital matchmaker, had an encounter of the unwanted kind. With intimate data spilling like wine at a Parisian café, users are braving the fallout of breached privacy while contemplating less exposed ways to find love.

+3 more stories

Open briefing →

The rundown

  1. 1 First up, it seems like FortiGate firewalls are starring in their own cyber-thriller as they've become victims of automated attacks, resulting in configuration data theft. Think of it as a hacker's time-traveling escapade from the future, challenging our concept of "patching up past mistakes."
  2. 2 Meanwhile, Spanish e-retailer PcComponentes is clapping back at rumors, denying claims of a data breach. In the world of e-commerce, being falsely accused of a hack might just be a dubious badge of honor.
  3. 3 In an unexpected comedic twist, a ransomware gang inadvertently left the door open for data recovery at 12 U.S. firms. It's like watching a heist movie where the gang forgets the loot and apologizes on their way out, digital slapstick at its finest.

+2 more stories

Open briefing →
Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.