Hacker wipes Romania's land registry database
17 hours ago
- A hacker breached Romania's cadastre agency, wiping the entire land registry database after a failed extortion attempt, halting the real-estate market.
- Hugging Face was hacked using an autonomous AI agent, stealing internal datasets and cloud credentials, while guardrails hindered their response analysis.
- A critical WordPress vulnerability (CVE-2026-63030, wp2shell) allows remote unauthenticated attackers to execute code, affecting versions since last December.
- Graykey maker Magnet Forensics sued a former employee for leaking an unpatchable iPhone exploit (usbliter8) to a rival company.
- Multiple high-profile breaches occurred, including Coca-Cola's ransomware attack, Qantas social engineering hack, and Suno's internal data leak.
- New malware and threats emerged, such as NadMesh botnet targeting AI infrastructure, ClickLock Stealer for macOS, and OAuth client ID spoofing campaigns.
- Arrests and legal actions include UK sentencing of Scattered Spider members, REvil hacker arrest in Armenia, and DHS seizing 30,000 SIM cards.
- APT activities involve UTA0533 exploiting SonicWall zero-days, Sandworm using ClickFix, and North Korean campaigns like Contagious Interview.
- Vulnerabilities like HollowByte in OpenSSL and a legacy bypass in Android via Gemini were disclosed, alongside patch releases and security guidance.
- Industry reports and podcasts covered trends, with discussions on AI in ransomware, exploit importance in cyber operations, and company security strategies.