Hacked dAily is the first AI-driven cybersecurity podcast, created by Cytadel Cyber and published daily for CISOs, security leaders, and decision-makers. Today’s briefing covers five developments with implications for enterprise risk, resilience, and security strategy.
1. Rust supply-chain attack
Hackers compromised the maintainer account for the popular arrayref crate and briefly poisoned it, along with append-only-vec and internment, to run malware during compilation. The campaign could steal credentials and host data across major operating systems, putting developers and projects in cryptography, blockchain, graphics, Ethereum, and Solana at risk; affected teams should assume compromise and rotate secrets.
2. N-able password vault flaw
N-able disclosed a vulnerability that could have exposed master keys in its password vault, potentially affecting managed service providers and their customers. Although the issue has been addressed and widespread exploitation was not reported, it demonstrates how one flaw in a centralized credential platform can create broad downstream exposure.
3. LockBit claims US Bank breach
US Bank is investigating LockBit’s claim that it stole data and has issued a September 3 pay-or-leak deadline. The bank says there is no current indication of internal compromise, but the allegation highlights extortion risk, third-party exposure, and the pressure to validate controls and contain reputational damage.
4. Cryptographic context injection targets AI
Researchers demonstrated an attack that hides malicious instructions in encrypted content, potentially tricking Grok and other AI systems into revealing chats and personal data. The technique shows how routine summarization and assistance workflows can become data-exfiltration paths when guardrails fail to detect concealed threats.
5. Zimbra flaw exploited in the wild
CERT Polska reports active exploitation of CVE-2026-73570, a high-severity Zimbra flaw affecting deployments with optional SNMP features enabled. Unauthenticated attackers can execute commands, creating opportunities for persistence, email and credential theft, and deeper network compromise; organizations should patch urgently and review affected systems.
Hacked Daily is sponsored by Cytadel, an offensive cyber assurance company specialising in AI-powered attacks. Cytadel’s expert-led Red Team Assessments follow real attack chains across people, identity and technology to verify whether they can become AI fraud or ransomware disruption. We verify your defences before attackers do. Learn more at cytadel.co.uk.