Skip to content
Hacked dAily
All Episodes

Hacked dAily Episodes

Every episode of Hacked dAily: 558 daily cybersecurity briefings and counting. Breaking news on breaches, ransomware and AI threats. Page 6 of 24.

The rundown

  1. 1 Our top story covers a global hacking campaign that defaced over 7,500 Magento sites, affecting high-profile entities like Toyota and FedEx, highlighting risks in using prevalent web platforms.
  2. 2 We also discuss CVE-2026-33017, a critical Langflow vulnerability exploited within 20 hours of disclosure, underscoring the critical need for urgent patch management to protect infrastructures.
  3. 3 Another development involves attackers leveraging GitHub Actions to spread infostealer malware via the Trivy vulnerability scanner, stressing importance in securing CI/CD pipelines from supply chain attacks.

+3 more stories

Open briefing →

The rundown

  1. 1 Google has set a 24-hour delay on sideloading unverified apps on Android, aimed at reducing malware risks and protecting users from scams. This proactive measure reinforces Google's dedication to enhancing user security.
  2. 2 Three individuals face charges for attempting to export AI tech to China, spotlighting national security concerns over tech proliferation. This case emphasizes the necessity of stringent export controls in safeguarding U.S. innovations in AI.
  3. 3 A UK police force suspends live facial recognition technology amidst findings of racial bias, igniting debates on its ethical and fair use. This underscores the critical need for oversight in deploying surveillance technologies equitably.

+3 more stories

Open briefing →

The rundown

  1. 1 Google introduces "Install Unknown Apps" for Android, offering flexibility for advanced users while managing security risks through layered permissions and warnings. This approach seeks to empower users responsibly without compromising device security.
  2. 2 Hackers are exploiting browser prompts to phish for biometric data, creating a new avenue for digital theft. This tactic urges organizations to bolster security protocols and educate users to counteract deceptive threats effectively.
  3. 3 Security experts identify 54 EDR killers using BYOVD tactics to exploit driver vulnerabilities for privilege escalation. Enterprises must rigorously vet driver updates to protect against these sophisticated security breaches.

+3 more stories

Open briefing →

The rundown

  1. 1 Nordstrom's recent breach involved unauthorized use of their email system to distribute cryptocurrency scams, risking customer trust. This highlights the need for stringent email security measures to protect corporate reputation.
  2. 2 Cisco's firewall zero-day vulnerability has been exploited to deploy Interlock ransomware, underscoring the urgency for immediate patching and robust defenses. Businesses must stay vigilant against evolving threats to maintain security.
  3. 3 A potent .NET AOT malware variant uses black box techniques, complicating detection and analysis. This advancement in malware evasion calls for enhanced cybersecurity detection capabilities.

+3 more stories

Open briefing →

The rundown

  1. 1 Today's top story reveals a significant misstep by Fancy Bear (APT28), a Russian cyber-espionage group, which inadvertently exposed their hacking techniques and infrastructure. This operational security failure allows cybersecurity defenders to enhance defenses against sophisticated cyber threats.
  2. 2 The UK Companies House incident exposed sensitive data of millions of firms, highlighting severe data privacy concerns and the potential for identity theft and financial loss, stressing the importance of robust corporate data protection measures.
  3. 3 INTERPOL warns of cybercriminals increasingly using artificial intelligence to improve the effectiveness of scams, including phishing, deepfake videos, and voice cloning, posing a severe threat and necessitating advanced defense mechanisms.

+2 more stories

Open briefing →

The rundown

  1. 1 Today's top stories:
  2. 2 A security flaw in AWS Bedrock's code interpreter could let attackers execute unauthorized code. This highlights the urgent need for robust cloud security measures to protect data integrity and maintain user trust.
  3. 3 The "Zombie ZIP" tactic manipulates ZIP file headers to evade antivirus software. Despite being dubbed CVE-2026-0866, it poses a minimal risk to isolated systems, as detection remains possible post-decompression.

+4 more stories

Open briefing →

The rundown

  1. 1 A major flaw in Bluetooth mesh networking via BitChat reveals potential cache poisoning and replay attacks. These vulnerabilities threaten secure IoT communications, emphasizing the necessity for immediate patches to protect private data integrity.
  2. 2 "CrackArmor" has been unveiled as a threat to systems using AppArmor, risking local privilege escalation to root. Local attacks jeopardize the security of Linux-based systems, pressing the need for urgent updates to preserve system integrity.
  3. 3 Operation CamelClone, a cyber espionage effort, targets global government and defense sectors. State-sponsored actors aim to access classified data, highlighting the urgent requirement for international cybersecurity cooperation.

+3 more stories

Open briefing →

The rundown

  1. 1 The FBI is facing scrutiny after a breach involving files linked to Jeffrey Epstein, reportedly caused by human error, raising fresh concerns about the protection of highly sensitive federal data.
  2. 2 Storm-2561 is targeting corporate users through fake VPN websites and trojanized installers, showing how search manipulation and trusted software impersonation remain effective tools for credential theft.
  3. 3 Researchers have identified new PhantomRaven attack waves targeting the npm ecosystem, underscoring the continued risk of software supply chain compromise for developers and organizations relying on open-source packages.

+3 more stories

Open briefing →

The rundown

  1. 1 Starbucks faces a breach impacting 889 employees, highlighting persistent credential theft risks and stressing enhanced data protection beyond perimeter defenses to prevent long-term fraud and identity theft.
  2. 2 Telus Digital confirms a breach by ShinyHunters, notorious for major data heists, emphasizing the critical need for robust cybersecurity to protect customer information and maintain compliance and trust.
  3. 3 Stryker's global cyber attack reveals vulnerabilities in healthcare's digital infrastructure, stressing the pressing need for enhanced security measures to protect patient data and ensure operational integrity.

+3 more stories

Open briefing →

The rundown

  1. 1 Meta has fortified anti-scam tools on WhatsApp, Facebook, and Messenger, targeting sophisticated fraud like brand spoofing and account hijacking. This move seeks to enhance user protection amidst intensifying regulatory scrutiny over $13.7 billion in cyber fraud cases.
  2. 2 Hackers exploit Cloudflare's CAPTCHA to mask phishing pages as real Microsoft 365 logins, posing severe risks to organizations reliant on email filters. This method elevates phishing credibility, stressing the need for advanced threat detection.
  3. 3 Loblaw discloses a breach in its PC Optimum loyalty program, leading to unauthorized personal data access while financial details remain secure. This highlights the necessity of robust cybersecurity in protecting consumer data.

+3 more stories

Open briefing →

The rundown

  1. 1 Today, we delve into a sophisticated supply-chain attack by UNC6426 on the nx npm package, exploiting software dependencies to gain AWS administrator access. This highlights urgent security gaps in the cloud infrastructure, demanding stronger measures in software supply chains.
  2. 2 In Europe, a legal advisor suggests banks should prioritize reimbursing cybercrime victims before claim legitimacy assessments. This could reshape financial institutions' approach to cyber incidents, enhancing consumer trust and accelerating relief.
  3. 3 Five malicious Rust crates have surfaced, exploiting CI/CD pipelines with AI bots to steal developer secrets. This emphasizes the need for securing development pipelines as attackers increasingly target automated systems, risking widespread breaches.

+3 more stories

Open briefing →

The rundown

  1. 1 First, MyFitnessPal, now under Cal AI, has endured a significant data breach affecting 3 million users, exposing personal information and highlighting persistent vulnerabilities in health apps. This breach underscores the urgency of robust security measures in our digitized world.
  2. 2 Next, telecom giant Ericsson has suffered a breach jeopardizing 15,000 employees and customers' sensitive data. This incident stresses the need for stringent cybersecurity protocols in critical industry sectors.
  3. 3 Introducing the 'BlackSanta' malware targeting HR departments, which cleverly sidesteps EDR systems. This tactic underlines the necessity for revised security measures and awareness training within organizations to counter such sophisticated threats.

+3 more stories

Open briefing →

The rundown

  1. 1 Today, ShinyHunters have breached Salesforce customer data, spotlighting vulnerabilities in cloud services and urging enterprises to enhance cybersecurity measures. Meanwhile, Hackerbot-Claw's attack on GitHub repositories, including those of Microsoft, emphasizes the growing threat posed by AI-driven cyber incidents and the need for strengthened digital defenses.
  2. 2 In Asia, web server vulnerabilities have been exploited to target critical infrastructure, using the Mimikatz tool, highlighting the need for robust protection to prevent national security and public safety disruptions. First Priority Group, a key U.S. emergency vehicle manufacturer, faces severe risks after a ransomware attack by Everest group, exposing sensitive operational data and posing challenges in law enforcement and public safety domains.
  3. 3 Finally, new research on AI security reveals vulnerabilities beyond traditional threats, as attackers leverage trial accounts to deploy malicious AI models. This exposure pushes organizations to reassess AI and cloud security strategies, focusing on protective measures to safeguard against internal breaches.

+1 more story

Open briefing →

The rundown

  1. 1 The White House has unveiled President Trump's Cyber Strategy, focusing on deterring cyber adversaries and fortifying national cybersecurity. This transformative approach is crucial for safeguarding U.S. economic stability and national security against growing cyber threats.
  2. 2 A critical vulnerability in Context7 MCP server poses risks of unauthorized data manipulation via AI assistants. This flaw underscores the urgency for securing AI infrastructures as dependency on artificial intelligence expands across sectors.
  3. 3 The emergence of INC's ransomware affiliate model allows cybercriminals to enhance campaign reach and efficacy, raising alarms among cybersecurity experts. This evolution in ransomware tactics necessitates robust defensive strategies to protect critical infrastructure.

+2 more stories

Open briefing →

The rundown

  1. 1 Anthropic's AI model Claude Opus 4.6 has identified 22 vulnerabilities in Firefox, highlighting gaps exploitable by malicious actors. This underscores AI's critical role in preemptively identifying threats, necessitating swift action to safeguard user data.
  2. 2 Cognizant's TriZetto Provider Solutions disclosed a breach affecting over 3.4 million patients, exposing gaps in healthcare cybersecurity and posing significant risks of identity theft. The breach, unnoticed for over a year, calls for improved network monitoring.
  3. 3 The case of Daniel Rigmaiden reveals the FBI's use of Stingray surveillance without warrants, fueling debates on privacy and legality. This underlines the need for transparency and legal frameworks governing law enforcement technologies.

+3 more stories

Open briefing →

The rundown

  1. 1 First up, Wikipedia was hit by a JavaScript worm, leading to widespread vandalism. This breach exposes vulnerabilities in user-generated platforms and urges reinforced security in content management systems to prevent similar threats.
  2. 2 Next, the FBI tackled suspicious network activities linked to surveillance systems. Although details are sparse, the event highlights enduring security challenges amid budget restrictions and staffing issues, stressing the need for resilient cybersecurity strategies within governmental entities.
  3. 3 Bing AI mistakenly promoted a fake OpenClaw GitHub repository housing info-stealing malware. This incident underscores the crucial need for enhanced vetting in AI search engines to avert the spread of malicious content and safeguard user security.

+3 more stories

Open briefing →

The rundown

  1. 1 GCHQ's discussions on a cyber threat firewall raise privacy debates and concerns over a potential VPN ban, with efforts focusing on children's online protection rather than adult restrictions, acknowledging the broad economic impact of comprehensive VPN prohibitions.
  2. 2 Telegram's rise as a cybercrime marketplace, fueled by encryption and anonymity, amplifies cybersecurity threats. This trend demands enhanced monitoring and measures against illicit activities affecting sensitive data spread.
  3. 3 Silver Dragon, linked to APT41, is targeting government entities using sophisticated tactics like Cobalt Strike payloads and Google Drive for command control. This highlights the national security risks and the imperative for heightened vigilance by government cybersecurity teams.

+3 more stories

Open briefing →

The rundown

  1. 1 Facebook users worldwide experience a major outage, blocking access and disrupting Meta's business services like Ads Manager and WhatsApp Business API. This highlights vulnerability in global connectivity and business operations, with no link to country-level internet issues confirmed.
  2. 2 In France, cybercriminals breach the Ministry of Health, stealing 15.8 million medical records. This breach underscores the need for robust cybersecurity to protect sensitive healthcare data and maintain trust in public institutions.
  3. 3 Drone attacks on AWS data centers in the Middle East reveal vulnerabilities in critical infrastructure. This raises security concerns, stressing the importance of securing digital operations in conflict-prone areas, given AWS's critical role for global enterprises.

+3 more stories

Open briefing →

The rundown

  1. 1 ShinyHunters breaches Dutch telecom Odido, leaking over 15 million records. The breach highlights vulnerabilities in safeguarding sensitive customer data, emphasizing the urgent need for robust cybersecurity against organized cybercrime.
  2. 2 Microsoft alerts users to a Remote Access Trojan hidden in compromised gaming utilities. These deceptive tactics stress the importance of vigilance and robust cybersecurity to protect individuals and organizations from unauthorized system access.
  3. 3 A Senate panel pushes forward legislation to bolster healthcare cybersecurity, addressing mounting threats to patient data and hospital operations. This initiative underscores the critical role of enhanced cybersecurity in protecting national health infrastructure.

+3 more stories

Open briefing →

The rundown

  1. 1 Today's top story: Europol's international crackdown has dismantled The Com cybercrime network, leading to 30 arrests. This highlights global law enforcement collaboration as crucial to protecting digital infrastructures from sophisticated threats impacting businesses and economies.
  2. 2 Researchers at Qrator Labs discovered the Aeternum botnet, which uses smart contracts on the Polygon blockchain for command-and-control. Its decentralized structure poses new challenges for cybersecurity, signaling a shift in how malware operators maintain resilience against takedowns.
  3. 3 The "ClawJacked Flaw" allows malicious websites to hijack OpenClaw AI agents through WebSocket connections, risking sensitive data and operational integrity. This reveals the ongoing need for robust web communication security in AI environments.

+3 more stories

Open briefing →

The rundown

  1. 1 Former President Trump has mandated the phase-out of Anthropic technology across federal agencies, citing national security concerns. This move highlights the critical need for balancing innovation with data protection in governmental systems.
  2. 2 Google reports threat actors are embedding AI into cyber attacks, with countries like China and Russia leading aggressive strategies. This evolution in tactics calls for enhanced protection of AI models, reshaping both offensive and defensive cyber landscapes.
  3. 3 Apple's iPhone and iPad have received NATO clearance for classified communications, marking a major milestone for consumer devices in defense applications. This demonstrates Apple's strong security protocols aligning with stringent military standards.

+2 more stories

Open briefing →

The rundown

  1. 1 Top Story 1: Global cybersecurity agencies urge immediate patching of a zero-day flaw in Cisco's SD-WAN software, allowing unauthorized access. Cisco's patch is crucial as enterprise networks face significant risks. Swift action is essential to safeguard sensitive data and operational integrity.
  2. 2 Top Story 2: DevChallenges.io suffers a breach, exposing sensitive user data on a hacking forum. The exposed information raises privacy concerns for developers and stresses the persistent risks of data exposure in online platforms.
  3. 3 Top Story 3: UAT-10027, a threat campaign, targets U.S. education and healthcare sectors using a backdoor called Dohdoor, hijacking HTTPS connections. Linked to North Korea's Lazarus Group, this underscores global cyber threat evolution and the need for advanced defenses.

+2 more stories

Open briefing →

The rundown

  1. 1 ShinyHunters has leaked data from 12.4 million CarGurus accounts after a failed extortion attempt, exposing users to phishing and identity theft risks. This incident highlights the importance of strong cybersecurity measures to protect consumer trust.
  2. 2 SolarWinds has issued patches for four critical vulnerabilities in its Serv-U software. Immediate application is crucial to prevent unauthorized access and maintain data integrity across enterprise environments.
  3. 3 Wynn Resorts has trusted attacker assurances that stolen employee data is deleted, raising concerns over corporate negotiation tactics and data security strategies. This case emphasizes the need for comprehensive cybersecurity response plans.

+3 more stories

Open briefing →
Newsletter

Subscribe to Our Newsletter

Stay ahead of cyber threats with our weekly insights. Get exclusive access to expert analysis, breaking news, and the latest cybersecurity trends delivered straight to your inbox.

By subscribing you agree to receive the Hacked dAily briefing. Unsubscribe any time: see the privacy notice.