Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily. Built for CISOs, security leaders, and executives, each episode distils the developments shaping cyber risk, resilience, and business decision-making.
1. Brevo Supply Chain Attack
A compromised Cloudflare API key allowed malicious scripts to reach Brevo properties and customer-embedded JavaScript, potentially affecting more than 100,000 websites. Fake verification prompts and possible unauthorized WordPress plugin installs show how one vendor compromise can spread malware and social-engineering risk at scale.
2. UK Police Data and Cloud Sovereignty
A Guardian investigation found sensitive police records, victim statements, and internal emails from more than 40 forces stored on Microsoft cloud systems previously flagged as vulnerable to foreign access. The findings raise major questions about data sovereignty, cloud governance, and whether protections for highly sensitive public-safety information are sufficient.
3. HEIF Heist Vulnerabilities
Researchers disclosed flaws in widely used image-decoding libraries that could enable data theft, memory corruption, and remote code execution across platforms and enterprise services. Because AI and cloud systems depend on these libraries, unpatched versions could expose accounts, tokens, repositories, and user data.
4. Government Impersonation Scams
FBI data shows fake police and government scams have caused more than $1.6 billion in losses since January 2025, with nearly 61,000 complaints. Threats involving arrest, jury duty, or licensing demonstrate why staff and customers must independently verify urgent demands for payment or sensitive information.
5. Settra Ransomware Targets Retail and Manufacturing
Huntress reports attacks using the Settra ransomware variant against retail and manufacturing organizations, with adversaries abusing remote tools, disabling recovery options, and deploying a vulnerable driver. The activity highlights how ransomware groups are strengthening post-compromise tactics to delay recovery and increase double-extortion pressure.
Hacked Daily is sponsored by Cytadel, an offensive cyber assurance company specialising in AI-powered attacks. Cytadel’s expert-led Red Team Assessments follow real attack chains across people, identity and technology to verify whether they can become AI fraud or ransomware disruption. We verify your defences before attackers do. Learn more at cytadel.co.uk.