Skip to content
Hacked dAily
All Episodes

Hacked dAily Episodes

Every episode of Hacked dAily: 558 daily cybersecurity briefings and counting. Breaking news on breaches, ransomware and AI threats. Page 5 of 24.

The rundown

  1. 1 Microsoft has issued patches for a critical SharePoint zero-day vulnerability and 168 other vulnerabilities. Active exploitation underscores the crucial need for rigorous patch management to protect systems and sensitive data.
  2. 2 President Trump pushes for the extension of Section 702 of the Foreign Intelligence Surveillance Act, sparking debate over balancing national security with privacy rights. This decision carries implications for intelligence operations and privacy policies.
  3. 3 A phishing campaign tricks YouTube creators with fake copyright strike notices, jeopardizing their Google credentials. The attack illustrates how compromised accounts can lead to reputational damage and loss of income for content creators.

+3 more stories

Open briefing →

The rundown

  1. 1 Today, we delve into a recent exploit on Booking.com, where cybercriminals leveraged social engineering to extract user credentials, underscoring the critical need for better user education in combating phishing techniques.
  2. 2 Next, we explore Omnistealer, a new infostealer utilizing blockchains like TRON and Binance Smart Chain for resilient malware hosting, complicating takedown efforts and compromising over 300,000 credentials across sectors.
  3. 3 In legal developments, Florida Attorney General James Uthmeier is probing OpenAI over potential ChatGPT involvement in a university shooting, spotlighting broader issues of AI tools influencing harmful behaviors and OpenAI's ongoing safety enhancements.

+3 more stories

Open briefing →

The rundown

  1. 1 Our Top Story: European fitness chain Basic-Fit has faced a data breach impacting the personal information of one million members. This highlights vulnerabilities within non-traditional targets and emphasizes the need for strong cybersecurity protocols to protect customer data.
  2. 2 In Latin America, the JanelaRAT malware has surged, with Brazil seeing 14,739 attacks targeting banks. This campaign threatens financial data, stressing the urgency for improved cybersecurity in emerging markets.
  3. 3 A new discovery reveals a 0-day vulnerability that can disable CrowdStrike's EDR solution, posing significant threats to endpoint security. This incident raises questions about the robustness of trusted EDR tools and the need for enhanced protection measures.

+2 more stories

Open briefing →

The rundown

  1. 1 China is integrating AI to reform education by preparing lessons and grading, aiming to streamline learning and reduce teachers' workloads. This could redefine global educational practices and demonstrates China's commitment to tech-driven innovation.
  2. 2 Ransomware groups now utilize 'EDR killers' to disable Endpoint Detection and Response systems, bypassing advanced security measures. This highlights the need for firms to strengthen cybersecurity defenses to prevent potential breaches and financial losses.
  3. 3 A joint operation by FBI Atlanta and Indonesian Police dismantled the W3LLSTORE phishing marketplace, disrupting a major hub for cybercriminals. The takedown showcases international efforts against cybercrime and the importance of solid defense strategies for business protection.

+3 more stories

Open briefing →

The rundown

  1. 1 Today, we explore the breach of a Chinese supercomputer, where a hacker has exfiltrated 10 petabytes of sensitive defense-related data. This highlights vulnerabilities in China's infrastructure and raises significant global security and diplomatic concerns.
  2. 2 In Hungary, a notable cyber blunder saw government systems compromised due to the weak password "FrankLampard." This incident stresses the urgent need for stringent password policies to safeguard critical data.
  3. 3 The FBI's retrieval of deleted Signal messages via iPhone settings unveils a potential privacy vulnerability in encrypted communications. This discovery calls for heightened awareness of device configurations to ensure messaging confidentiality.

+3 more stories

Open briefing →

The rundown

  1. 1 Fake Anthropic Website: An impersonating site spreading PlugX malware has targeted users of Anthropic's Claude. The spoofed site deceives users into running a trojanized installer, emphasizing the paramount importance of safe download practices.
  2. 2 VENOM Phishing Campaign: Sophisticated phishing tactics target senior executives to steal Microsoft credentials. This exposure risks unauthorized access to high-level corporate data, stressing the urgency for enhanced security measures.
  3. 3 Sockpuppeting Jailbreak: A single-line exploit circumvents security in 11 major AI models, affecting ChatGPT and others. OpenAI and AWS Bedrock have responded with blocks, highlighting the need for consistent vulnerability management.

+2 more stories

Open briefing →

The rundown

  1. 1 Meta's data protection challenges intensify as a former employee allegedly accessed 30,000 private Facebook images, surfacing persistent insider threats and questioning existing cybersecurity frameworks.
  2. 2 A data breach at MyLovely.AI has exposed 106,000 users' sensitive information to the dark web, escalating concerns over privacy in rapidly growing AI applications and exposing users to potential doxxing and sextortion.
  3. 3 A cyber attack on Zephyr Energy rerouted £700,000 meant for a contractor, spotlighting vulnerabilities in business communication systems and the pressing need for stringent security measures.

+2 more stories

Open briefing →

The rundown

  1. 1 Anthropic unveils Claude Mythos, a revolutionary AI model under Project Glasswing aiming to preemptively secure software from cyber threats. This collaboration with major security players elevates software defenses but brings potential misuse concerns.
  2. 2 AMAInterview.ai suffers a data breach, exposing over 24,000 user records to cybercriminals. This incident stresses the urgent need for robust data security practices in digital platforms managing sensitive personal information.
  3. 3 Google introduces API keys for its Gemini service on Android, enhancing connectivity and user convenience. This move aligns with Google's strategic integration of AI, promising seamless user experiences and streamlined tech operations.

+2 more stories

Open briefing →

The rundown

  1. 1 T-Mobile has confirmed a data breach exposing customer information, including names, addresses, and phone numbers, but reported no sensitive data was compromised. This highlights the persistent vulnerabilities in telecommunications and underscores the need for enhanced cybersecurity measures.
  2. 2 A major outage on April 3 paralyzed Russian banking apps, affecting institutions like Sberbank and Alfa-Bank, due in part to new VPN restrictions. As businesses faced disruptions, the event underscores Russia’s effort to strengthen internet control, impacting online freedoms.
  3. 3 The Space Bears ransomware group attacked Brooklands of Mornington, threatening to leak sensitive employee and guest data if extortion demands aren't met. This breach emphasizes increased ransomware threats to the hospitality sector, stressing the need for stringent cybersecurity defenses.

+2 more stories

Open briefing →

The rundown

  1. 1 In today's top stories:
  2. 2 A corporate data breach via an internet-connected coffee machine highlights the vulnerabilities of IoT devices. Cybercriminals accessed the network through the appliance, stressing the essential need for stringent security on all connected devices to safeguard sensitive data.
  3. 3 Italy's Uffizi Gallery reported a cyberattack with no significant data compromise, spotlighting the cyber challenges cultural institutions face in safeguarding digital assets against increasing threats.

+4 more stories

Open briefing →

The rundown

  1. 1 A breach exposed vulnerabilities in npm's open-source ecosystem after an attacker used a fake Microsoft Teams prompt to control the popular Axios library. This stresses the need for stronger authentication and vigilance against phishing to protect software supply chains.
  2. 2 Crunchyroll faces a data breach, compromising over a million accounts and highlighting vulnerabilities in digital platforms and the importance of robust cybersecurity measures to protect user data and maintain trust.
  3. 3 A discovered vulnerability in the Mongoose web server software allows potential remote code execution on IoT devices, risking unauthorized access. This flaw could disrupt systems globally, underscoring the need for prompt security patches.

+2 more stories

Open briefing →

The rundown

  1. 1 ICE's use of Paragon spyware has ignited debates on constitutional compliance, civil liberties, and counterintelligence. With calls for transparency, the controversy signals potential national security implications.
  2. 2 Over 14,000 F5 BIG-IP APM instances remain unpatched, exposing businesses to RCE attacks. This highlights the pressing need for rigorous patch management and proactive defense strategies.
  3. 3 Google researchers reveal "Coruna," an iPhone hacking toolkit exploiting 23 iOS vulnerabilities, allegedly used by Russia. This discovery raises alarms about the spread and control of state-sponsored cyber tools.

+3 more stories

Open briefing →

The rundown

  1. 1 The FBI warns against Chinese mobile apps due to serious privacy and security risks, highlighting concerns about possible unauthorized data access and espionage, emphasizing the need for vigilance in app selection amidst geopolitical tensions.
  2. 2 ShinyHunters claims a major breach at Cisco Systems, involving over 3 million Salesforce records linked to high-profile entities like the FBI, IRS, and NASA. This raises alarms about potential targeted attacks, urging heightened security measures for companies using Salesforce.
  3. 3 The emergence of EvilTokens exacerbates phishing attacks on Microsoft device codes, allowing cybercriminals to bypass two-factor authentication. This trend underscores the need for enhanced security protocols against sophisticated token-based threats.

+2 more stories

Open briefing →

The rundown

  1. 1 Dubai International Airport faces claims of a data breach by Nasir Security, allegedly infiltrating the hub's intelligence systems. This breach could pose severe security risks and privacy threats, emphasizing vulnerabilities in global infrastructure.
  2. 2 A new service helps ransomware gangs monetize stolen data, heightening financial and reputational risks for victims. This reveals a complex threat landscape, urging stronger cybersecurity defenses and response plans.
  3. 3 Lloyds Banking Group's IT glitch exposed sensitive data of nearly 500,000 customers, highlighting severe data privacy issues and potential regulatory scrutiny. Institutions must enhance cybersecurity to prevent such breaches.

+2 more stories

Open briefing →

The rundown

  1. 1 Today, discover how Google’s new feature in Google Drive for desktop automatically scans for ransomware threats, bolstering defenses as ransomware attacks surge globally.
  2. 2 A dark web listing claims possession of 375 terabytes of data from Lockheed Martin, priced at $600 million. This could have severe national security implications, emphasizing the vulnerability of defense contractors.
  3. 3 Researchers reveal the TeamPCP group’s exploitation of a tainted Telnyx SDK to steal credentials via a fake ringtone file. This highlights the importance of maintaining third-party software integrity.

+3 more stories

Open briefing →

The rundown

  1. 1 Today, the U.S. government's ban on foreign-made routers in critical infrastructure has sparked industry debate. Critics argue it's less about security and more about protecting domestic manufacturers, potentially affecting trade and technological innovation.
  2. 2 A vulnerability in the Smart Slider plugin threatens over 500,000 WordPress sites by potentially exposing sensitive files. This highlights the need for regular plugin updates and rigorous security reviews to protect digital assets.
  3. 3 EtherRAT’s integration with the Ethereum blockchain in the EtherHiding technique is transforming cyber threat landscapes. This method complicates detection and stresses the importance of staying updated on sophisticated threats leveraging decentralized networks.

+3 more stories

Open briefing →

The rundown

  1. 1 FBI Director Christopher Wray's personal data was reportedly compromised by the cyber group Handala as part of an offensive targeting high-profile officials. This breach signifies growing cyber threats at national security levels, urging enhanced protective strategies for government leaders.
  2. 2 Apple warns users of older iPhones and iPads about active exploits. Critical updates are necessary as outdated devices remain vulnerable to attacks like Coruna and DarkSword, stressing the crucial nature of regular software updates.
  3. 3 TA446's spear-phishing campaign leverages the DarkSword iOS Exploit Kit, aiming at high-value targets. This marks a significant evolution in threat actor strategies, necessitating increased vigilance and protective measures for both organizations and individuals.

+3 more stories

Open briefing →

The rundown

  1. 1 Today's top stories include a cyberattack on the European Commission's cloud systems, resulting in unauthorized data access and highlighting cybersecurity challenges for EU entities. In the Netherlands, a phishing attack breached the Dutch Police, emphasizing the pressing need for robust cybersecurity and employee training to prevent national security risks.
  2. 2 A fraudulent website mimicking Avast has been reported, tricking users into downloading the Venom Stealer malware, underscoring the importance of vigilance against phishing scams exploiting trusted brands. South Korean AI company ActionPower faces an attack from the Crypto24 group, spotlighting ransomware risks that threaten tech firms with operational disruptions.
  3. 3 Lastly, the "Mythos leak" at Anthropic brings attention to Phishing 3.0, a sophisticated cyberattack evolution demanding advanced security strategies from organizations.

+1 more story

Open briefing →

The rundown

  1. 1 Apple's latest iOS update mandates age verification for UK users, sparking privacy concerns by requiring personal data to access specific apps. Critics liken this move to 'ransomware,' citing major implications under the UK’s Online Safety Act.
  2. 2 Google predicts quantum computers could break current encryption by 2029, threatening global data security. This highlights the urgent need for quantum-resistant algorithms to protect sensitive digital assets.
  3. 3 Ajax Football Club suffers a cyberattack, compromising fans’ personal data and ticketing systems. The breach underscores sports organizations' need for strong cybersecurity to safeguard data integrity and reputation.

+3 more stories

Open briefing →

The rundown

  1. 1 Today’s top story: Baltimore sues Elon's xAI for allegedly distributing deepfake videos, spotlighting the challenges and potential legal ramifications of AI technologies in spreading disinformation.
  2. 2 The National Association on Drug Abuse Problems reports a breach impacting 90,000 individuals, exposing sensitive personal data. The incident urges the need for heightened cybersecurity and consumer vigilance.
  3. 3 Silver Fox campaigns adopt dual espionage tactics, blending cyber and human intelligence. This evolution stresses the importance of comprehensive defenses against both digital and human intelligence threats.

+3 more stories

Open briefing →

The rundown

  1. 1 Microsoft warns of a sophisticated phishing campaign exploiting Remote Monitoring and Management software, targeting 29,000 users by posing as the IRS. This emphasizes the urgent need for robust cybersecurity defenses against deceptive tactics.
  2. 2 Authorities dismantled 373,000 dark web sites engaged in hosting child sexual abuse material. This highlights the need for international collaboration and advanced enforcement to combat cybercrime effectively.
  3. 3 Mazda disclosed a data breach from unauthorized access to its warehouse management system, impacting 692 employee and partner records. The incident underscores the importance of addressing security vulnerabilities and the repercussions of data exposure.

+2 more stories

Open briefing →

The rundown

  1. 1 Foster City, California, reels from a ransomware attack disrupting municipal services, highlighting the vulnerability of smaller municipalities to cyber threats. A state of emergency has been declared, emphasizing the importance of robust defenses for public entities against data breaches.
  2. 2 A new malware strain targets Cobra DocGuard users by disguising as legitimate documents, compromising sensitive data. Organizations must enhance security measures to protect critical data environments from these deceptive threats.
  3. 3 The GlassWorm cyber campaign exploits the Open VSX registry with sleeper extensions resembling Visual Studio Code enhancements, raising alarms over open-source security. This case underscores the need for vigilant monitoring of software repositories globally.

+3 more stories

Open briefing →
Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.