Risky Bulletin

Risky Bulletin: Hacker wipes Romania's entire land registry database

9 min
Jul 20, 20261 day ago
Listen to Episode
Summary

This episode covers major cybersecurity incidents including Romania's land registry database wipe, breaches at Hugging Face and Suno, a critical WordPress vulnerability affecting 41% of websites, and arrests of members from Scattered Spider and Reval ransomware groups. The episode highlights emerging threats from AI-powered attacks, supply chain compromises, and unpatchable hardware exploits.

Insights
  • Insider threats remain critical: legitimate credentials are being weaponized by attackers, as seen in Romania's breach, requiring zero-trust architecture beyond perimeter security
  • AI platforms are becoming attractive targets due to their data processing pipelines and cloud infrastructure, requiring specialized security for ML systems
  • Hardware-level exploits (like the iPhone ROM bug) represent a new frontier in attack sophistication that cannot be patched, forcing device-level mitigations
  • Critical infrastructure vulnerabilities in widely-used software (WordPress, OpenSSL) can affect millions of organizations simultaneously, necessitating rapid patching protocols
  • Law enforcement is increasingly coordinating internationally to prosecute cybercriminals, with multiple jurisdictions pursuing members of the same hacking groups
Trends
Rise of autonomous AI agents being weaponized for reconnaissance and lateral movement in enterprise networksInsider threat escalation: employees leaking proprietary exploits to competitors, indicating IP protection gapsHardware vulnerabilities becoming more prevalent and unpatchable, shifting security burden to software mitigationsRansomware groups diversifying targets beyond finance to consumer goods (Coca-Cola) and critical infrastructureSupply chain attacks through VPN software and package managers (NPM worms) compromising entire enterprise networksData scraping at scale for AI training creating legal and security vulnerabilities for AI platformsInternational law enforcement coordination improving, resulting in multi-year prison sentences for cybercriminalsCritical infrastructure security gaps exposed through social engineering and contractor access abuseZero-day exploitation in VPN and network appliances (SonicWall, VIPNet) targeting enterprise perimetersDelayed breach disclosure timelines (Estee Lauder ~1 year) indicating detection and response challenges
Topics
Land Registry Database SecurityInsider Threat ManagementAI Platform SecurityRansomware Attack ResponseSocial Engineering AttacksWordPress Vulnerability ManagementiPhone Hardware ExploitsVPN Security VulnerabilitiesZero-Day ExploitationInternational Cybercrime ProsecutionData Scraping and AI TrainingSupply Chain SecurityBreach Disclosure TimelinesOpen Source SecurityCritical Infrastructure Protection
Companies
Romania Land Registry
Entire database wiped by hacker Byte2Breach; real estate apps offline for a week; stolen data offered for sale
Hugging Face
Breached using autonomous AI agent; internal datasets and cloud credentials stolen; customer data not exposed
Coca-Cola
Suspended Fairlife dairy product production in US following ransomware attack; Canadian lines unaffected
Qantas
2024 hack traced to social engineering; 5 million customer records exfiltrated via CRM platform compromise
Suno
AI music generator breached; internal files reveal scraping of millions of songs from YouTube Music, Deezer, Genius
Estee Lauder
Oracle EBS platform breach disclosed nearly 1 year after incident; separate 2023 breach also occurred
Magnet Forensics
Suing former employee Mario Del Gaudio for leaking proprietary iPhone exploit details to competitor Paradigm Shift
Paradigm Shift
Received leaked iPhone exploit details from Magnet Forensics employee; publicly disclosed as US Blitterate
Transport for London
Hacked by Scattered Spider members Tala Joubert and Owen Flowers; caused months of disruptions, £39M damages
Rockstar Games
Hacked by Lapsus group member Arjen Kurtash; GTA 5 source code and GTA 6 gameplay released
Infotex
VIPNet Enterprise VPN owner; confirmed backdoor attacks via compromised VPN node and update mechanism
SonicWall
SMA appliances exploited via two zero-days (SSRF and code injection) by UTA0533; patches released
WordPress
Critical SQL injection vulnerability in REST API (WP2Shell) affects 41% of all internet sites; remote code execution
OpenSSL
Holobyte vulnerability allows crash via 11-byte payload; forces memory allocation before TLS handshake
Medibank
2022 ransomware attack suspect Alexander Ermakov arrested; unclear if same person or different individual with same name
Apple
iPhone exploit (MSG/US Blitterate) affects A12 and A13 chips; hardware bug that is unpatchable
Oracle
EBS platform targeted by CLOP hacking group; Estee Lauder and other companies breached via this service
Searchlight Cyber
Discovered critical WordPress REST API SQL injection vulnerability tracked as WP2Shell
Okta
Discovered Holobyte OpenSSL vulnerability allowing remote denial of service attacks
People
Katalin Kimpano
Prepared the Risky Bulletin episode content
Claire Aird
Read and presented the Risky Bulletin episode
Zakaria Majoub
Identified by Keller as Byte2Breach; breached Romania land registry and Sweden e-government portal
Mario Del Gaudio
Leaked proprietary iPhone exploit details to competitor Paradigm Shift; subject of lawsuit
Tala Joubert
Sentenced to 5.5 years for hacking Transport for London; also charged in US for extorting 47 companies
Owen Flowers
Sentenced to 5.5 years for hacking Transport for London in 2024
Alexander Ermakov
Arrested at Yerevan airport; suspected of Medibank ransomware attack in 2022; identity disputed
Arjen Kurtash
Transferred from secure hospital to standard prison; awaiting trial for Rockstar Games hack and GTA source code leak
Full Transcript
A hacker wipes Romania's entire land registry database, Magnet Forensics sues a former employee for leaking an iPhone exploit, an autonomous AI agent hacked Hugging Face, and an unauthenticated remote code execution bug was finally found in WordPress. This is the Risky Bulletin, prepared by Katalin Kimpano and read by me, Claire Aird. Today is the 20th of July and this podcast episode is brought to you by Thinkst, the makers of the much-loved Thinkst Canary. In today's top story, a hacker has breached and wiped Romania's entire land registry database. Romania's real estate apps and websites have been offline for a week. Sources told Risky Business the hacker gained access using valid credentials and did not try to extort the agency. The stolen data is now being offered for sale on a known hacking forum. Officials say they're working to rebuild the agency's network. The intrusion was carried out by a hacker known as Byte2Breach, who also targeted Sweden's e-government portal this year. Security firm Keller identified the hacker as Zakaria Majoub, an individual based in Algeria. In other news, a threat actor breached AI platform Hugging Face, using an autonomous AI agent last week. The attacker used exploits in the platform's data processing pipeline, then pivoted to the company's internal systems. Hugging Face says internal data sets and some cloud credentials were stolen, but customer data was not exposed. Coca-Cola has suspended production of its Fairlife dairy product lines in the US following a ransomware attack. The company disclosed the incident in an SEC filing this week. The company's Canadian production lines are unaffected. No ransomware group has taken credit for the incident yet. Last year's hack of Australian airline Qantas has been traced back to a social engineering attack. Hackers called an overseas contractor posing as the Qantas IT team to access the Qantas CRM platform and exfiltrate the data of 5 million customers Australia Information Commissioner says Qantas took all the correct steps to protect customer data and will not be taking further action. A hacker has breached AI music generator platform Suno and has dumped its internal files and documents online. The files allegedly reveal that Suno scraped millions of songs and lyrics from music platforms, including YouTube Music, Deezer and Genius. The files include source code and detailed scraping instructions. Several music industry groups have sued Suno in the last year over training its song generator on copyrighted material. Suno is believed to have been hacked after being compromised with the Shaihalud NPM worm. Hackers stole customer data from cosmetic giant Estee Lauder's Oracle e-business suite platform last year. The company has just disclosed the breach to US state officials, almost a year after it occurred. The company also suffered a separate breach in 2023. The CLOP hacking group targeted Oracle EBS service in a hacking spree last year. The US government plan to rotate cybersecurity employees between federal agencies has failed. Only eight employees participated in the Federal Rotational Cyber Workforce Program since its launch in 2022. The program was designed to allow employees to develop new skills before returning to their original agencies. The Trump administration has launched a new program to help coordinate the disclosure and patching of vulnerabilities in open source projects and critical infrastructure. The so-called Gold Eagle program was designed to receive bug reports at scale using AI tools and frontier AI models. CISA, the Treasury Department and the Pentagon are involved in the program. And yeah, Gold Eagle, we're confused about the name too. Grey key maker Magnet Forensics is suing a former employee for leaking details about a proprietary iPhone exploit. Magnet claims Mario Del Gaudio shared details of the exploit with his new employer rival company Paradigm Shift The exploit was referred to inside Magnet as MSG but Paradigm Shift disclosed it publicly as US Blitterate. The exploit allows attackers to run malicious code inside the secure ROM of Apple devices with A12 or A13 chips. It's a hardware bug and unpatchable. Two members of the Scattered Spider hacking group have each been sentenced in the UK to five and a half years in prison. Last month, Tala Joubert and Owen Flowers both pleaded guilty to hacking the London Public Transport Authority in 2024. The hack caused months of disruptions at Transport for London and resulted in damages of £39 million. Joubert has also been charged in the US over hacking and extorting 47 American companies and seeking ransoms of at least $115 million. Armenian authorities have arrested a suspected member of the Reval ransomware group. Alexander Ermakov was arrested late last month at the Yerevan airport on an Interpol warrant. A man named Alexander Ermakov is also the main suspect behind the ransomware attack on Australia's Medibank insurer in 2022. Russian media claims that Armenian authorities have arrested a different man with the same name and the other Ermakov is in Russia serving a restriction of freedom sentence that prevents him travelling abroad. Three cyber scam compounds have been raided in Timor-Leste's capital city, Dili. Police arrested 253 suspects, most of whom are Chinese and Indonesian nationals. Authorities also raided a fourth separate compound last month. A member of the Lapsus Hacking Group has been transferred from a secure hospital to a standard prison in the UK. Arjen Kurtage is awaiting trial for hacking Rockstar Games in 2022. He's also accused of releasing GTA 5 source code and GTA 6 gameplay. Kirtash was diagnosed with autism and transferred to hospital custody in December 2023. A hacking group is planting backdoors inside Russian companies using the VIPNet Enterprise VPN software The attackers compromised one VPN node before exploiting the software update mechanism to install the backdoor across entire networks VIPNet owner Infotex has confirmed the attacks and released security updates. Similar attacks took place in April last year. A hacking group tracked as UTA0533 is behind two zero days that are being exploited in SonicWall SMA appliances. The zero days are an SSRF and a code injection vulnerability. They grant an attacker root level access to the devices. The attacks began in late June and are deploying malware designed specifically for SonicWall SMA VPN appliances. SonicWall released patches for both of the vulnerabilities last week. WordPress has patched one of the most critical bugs ever found in the project's code. The vulnerability is an SQL injection in the WordPress REST API. It can be exploited by remote, unauthenticated attackers to run malicious code on any WordPress site. The issue can be exploited without any preconditions and impacts all WordPress versions released since December. WordPress powers more than 41% of all internet sites. The bug was discovered by Searchlight Cyber and is tracked as WP2Shell. And finally, a new vulnerability can crash open SSL service using an 11 bytes payload. The attack forces service to allocate huge amounts of memory before any secure TLS handshake begins and can be exploited remotely by unauthenticated attackers. The OpenSSL Project released patches for the bugs last month. The vulnerability was discovered by Okta and is named Holobyte. And that is all for this podcast edition. Today's show was brought to you by our sponsor, Thinkst Canary. Find them at canary.tools. Thanks for your company. Thank you.