2025-06-06: Chrome Extensions Leak, Passion.io Exposed, PumaBot Strikes IoT & UNC6040 Vishes Salesfore
Hacked dAily6 Kesä 2025

2025-06-06: Chrome Extensions Leak, Passion.io Exposed, PumaBot Strikes IoT & UNC6040 Vishes Salesfore

Welcome to Hacked dAily, the first AI-Driven Cybersecurity Podcast where we inject some levity into the digital drama of the day. Buckle up for today’s edition: Chrome extensions are having a field day with user data, proving once again that your privacy might be less secure than the frosting on a cupcake. Meanwhile, Passion.io creators are learning that exposure isn't just for photographers, as 3.6 million users found their info scattered across the tech universe like confetti. And in a twist of technological irony, the PumaBot Linux botnet decided to explore its voyeuristic side, targeting IoT surveillance devices. Perhaps the next great reality show will be "Watch Us Get Watched," where your Wi-Fi password '12345' gets a leading role. Elsewhere, ransomware and USB attacks are hitting operational tech systems with the enthusiasm of a sugar-high toddler at a piñata party. As IT departments transform into USB guardians, remember: the next "free USB" you find might be less free and more fiendish. Finally, meet UNC6040, the culprits making life difficult for Salesforce users with vishing and dubious data loader apps. With all that creativity, you'd swear they were aiming for a Silicon Valley startup—if only corporate mischief wasn't their apparent calling. Catch all this and more in today’s episode, right here on Hacked dAily!This episode is sponsored by Cytadel Cyber. Specialist in Ransomware Readiness Assessments, Threat Intel-Led Red Teaming, AI DeepFakes, AI Voice Cloning and AI Vishing Simulations. Cyatdel helps you test your cyber resilience against the threats of today, keeping your data secure. Checkout cytadel.co.uk for more information.

Jaksot(500)

17-May-2024: MediSecure Ransom Attack, Intel Patches 90 Flaws, Turla Strikes Again

17-May-2024: MediSecure Ransom Attack, Intel Patches 90 Flaws, Turla Strikes Again

Welcome to today's episode of "Cyber War Room," your go-to daily podcast for the latest and most critical updates in the world of cybersecurity. In today's lineup: First up, MediSecure, a prominent electronic prescription provider in Australia, has become the latest victim of a ransomware attack linked to a third-party vendor. This serious breach compromised the personal and health information of numerous individuals. We will dive into the immediate actions taken by the company and the ongoing investigations. Next, we spotlight tech giant Intel, which has recently issued 41 security advisories covering more than 90 vulnerabilities across its product spectrum. These vulnerabilities pose significant risks, and we’ll discuss the urgent call for users to update their systems. Then, we turn our attention to the Turla Group’s latest cyber espionage maneuvers. Using sophisticated tools named LunarWeb and LunarMail, the group has been targeting European diplomatic missions, breaching sensitive communications. We’ll examine the implications of these targeted attacks. In other news, North Korean hackers are exploiting Facebook Messenger to launch malware attacks, showcasing yet another creative method of cyber intrusion through popular social platforms. And finally, we wrap up with a concerning discovery within the Linux community, where maintainers unearthed an SSH-backdoor that went unnoticed for two years, reflecting serious vulnerabilities in security practices across open-source platforms. Stay tuned as we unpack these stories, offering insights into how these developments could impact cybersecurity strategies and data protection efforts globally. Join us in the "Cyber War Room" to stay informed and prepared against the ever-evolving cyber threat landscape.

17 Touko 20242min

16-May-2024: Santander Breach, Chrome Vulnerability CVE-2024-4761, FBI Seizes BreachForums

16-May-2024: Santander Breach, Chrome Vulnerability CVE-2024-4761, FBI Seizes BreachForums

Today on "Cyber War Room," we delve into the latest casualties and maneuvers in the ongoing global cyber conflict. Starting off, we discuss a significant data breach at Banco Santander, where customers' sensitive information including names and financial details are at risk, prompting a thorough investigation by the bank. Next, we cover the urgent zero-day vulnerability CVE-2024-4761 discovered in Google's Chrome browser. With the exploit already in active use by cyberattackers, listeners are advised to update their browsers immediately to prevent potential compromises. Our third story showcases the FBI’s tactical victory with the takedown of BreachForums, a hub for cybercriminals to trade stolen data, demonstrating a robust effort against online black markets. In European affairs, we explore an ongoing investigation into newly discovered backdoors in a government network, believed to be placed by Russian hackers aiming to infiltrate and possibly disrupt key state functions. Finally, we delve into how APT29, a notorious cyber espionage group, has targeted German political circles using sophisticated malware known as WINELOADER, with aims to influence and spy on significant political processes. Join us daily on "Cyber War Room" for up-to-date discussions on these critical developments affecting the cybersecurity landscape worldwide. Stay informed and stay secure.

16 Touko 20242min

15-May-2024: Major Cyber Attacks Hit Singing River and HK Colleges; Ransomware Surge

15-May-2024: Major Cyber Attacks Hit Singing River and HK Colleges; Ransomware Surge

Welcome to today's episode of "Cyber War Room." In our top story, the Singing River Health System in Mississippi faces a serious breach from a Rhysida ransomware attack impacting nearly 900,000 individuals, disclosing sensitive personal and medical information. Moving eastward, the Hong Kong College of Technology reels under a cyberattack with over 8,000 students’ data compromised and found on the dark web, stressing the growing cyber threats in educational sectors. In more technical revelations, researchers uncover a devious social engineering campaign by attackers using Black Basta ransomware, employing spam and false IT communications to infiltrate organizations, reflecting a troubling trend in cyberattack sophistication. Elsewhere, a shift in tactics has cybercriminals using malvertising, deepfakes, and popular platforms like YouTube to perpetrate scams, marking an evolution from traditional phishing approaches to more complex digital deception. Wrapping up, cybersecurity specialists have flagged a new menace in malware with trojanized versions of the trusted software tools WinSCP and PuTTY - a reminder of the continuous need for vigilance in verifying source authenticity to prevent data theft and ransomware attacks. Stay tuned to "Cyber War Room" as we delve deeper into these issues and more to keep your data safe in the turbulent seas of cyberspace.

15 Touko 20243min

14-May-2024: NATO Cyber Red Line, Black Basta Hits 500, NHS Data Leak Concerns

14-May-2024: NATO Cyber Red Line, Black Basta Hits 500, NHS Data Leak Concerns

Welcome to today's episode of "Cyber War Room." Today, we delve into the latest and pertinent cyber threats and responses shaping our digital world. Our top story: NATO has drawn a cyber red line in response to escalating tensions with Russia, signaling a robust stance against potential cyber aggression. This highlights their resolve to enhance and defend the alliance's cyber infrastructure. In our second major news item, the Black Basta ransomware group's recent activities have compromised over 500 organizations worldwide. This surge in cyber attacks emphasizes the need for strengthened cybersecurity protocols across various sectors. Additionally, we cover the alarming incident where personal data from the National Health Service appeared on the dark web. This breach has exposed sensitive patient information, prompting urgent calls for increased data protection measures. Moving on to other critical updates, cybersecurity experts are currently addressing the spread of Mallox ransomware through vulnerabilities in MS-SQL servers. This issue stresses the importance of securing database systems against such invasive attacks. And finally, we explore the growing use of DNS tunneling techniques by hackers to conduct covert network scans and track victims, a method that complicates the detection of illicit activities and data breaches. Stay tuned as we continue to monitor these developments and provide you with crucial insights on how to safeguard your digital environments.

14 Touko 20242min