If your production system at most runs a backup to a drop site, then your backup facilities pull down versioned backups from there, you can better ensure older backup files are intact. More so by not allowing the two to see each other at all and not using backup accounts from a system that can access production resources.
So it seems not all has been lost. I was worried about the societal implications of being unable to prove land ownership but it seems that may be avoided.
ANCPI announced that it had begun migrating its applications to Romania’s Government Cloud. The operation is being coordinated by the Special Telecommunications Service (STS) and is expected to be completed on Wednesday, July 22.
After the migration, authorized institutions will inspect the applications and data and prepare a report on the condition of the systems and any additional measures required. Based on that report, ANCPI will announce an estimated date for restoring its applications. Services will be brought back online gradually, according to operational priorities.
ANCPI says it is rebuilding its database from backup copies stored in several locations. The agency rejected reports suggesting that it did not have sufficient backups, explaining that the use of multiple storage locations provides redundancy and allows data to be restored after cybersecurity incidents.
According to ANCPI, affected systems must remain isolated until every identified vulnerability has been addressed. Although shutting down the services has caused temporary inconvenience, the agency says the measure was necessary to protect the data and ensure that operations restart safely and reliably.
The restoration of the IT infrastructure is described as a complex process being conducted in cooperation with the relevant authorities. ANCPI has also confirmed that a criminal investigation is underway, but no official conclusions can yet be released.
The agency warned that claims circulating publicly about the alleged consequences of the attack are not based on official information and do not reflect the current state of the investigation.
This, to me, is the more interesting bit of the article.
I don't really know what a good solution looks like, but yeah, that's annoying.
Security firm KELA... has doxxed the hacker as Zakaria Mahdjoub, an individual from Oran, Algeria.
If I was an evil hacker, I would only hack countries my country hated or did not have extradition agreements with. Like the Russian hackers do.Algeria has a extradition treaty with Romania:
https://periodicos.processus.com.br/index.php/egjf/article/v...
Specifically:
- government gives IT/data contracts to cronies
- cronies don't actually do any real security work to protect the data
- things like this happen
Posts and screenshots apparently by the alleged attacker show "P@ssw0rd" and other well-known / readily-guessable passwords from the hacked systems:
<https://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked...>
<https://drive.google.com/file/d/1iZc93XfViOk7izusgIG1ni7Kmsx...>
Originally noted, without references, by ExoticPearTree here: <https://news.ycombinator.com/item?id=48978836>.
NB: If you're going to point out stupidity verging on cliched tropes, do so with sufficient evidence that it doesn't read as a tired and unsubstantiated canard. The fact that this does happen (and apparently did) doesn't mean it's necessarily the case in any specific instance.
There's a growing (retarded) perspective, not only here in Romania but in most of the EU, that we must digitalize at all costs; this itself is obviously not a problem, but it usually comes with the removal of the "traditional" options too. The same goes for payments (removal of cash) and basically every aspect of the administration/society where this could be applied. The most recent concrete example for Romania is the mandatory digital signature by ANAF (IRS equivalent) for all companies.
Unlike other regions of the West: NA/WE/rest of the West (SK, JP, etc.), in EE, people (*younger generations, explained below) don't often think about the aspects of confidentiality that much, or if they do, they usually apply it incorrectly (either IRL [filming in public] or online ["I've accepted a draconian TOS that gives the company rights to all of my data, but I haven't actually read any of it, and now I'm invoking my "GDPR rights" against said company."]).
It does not take a genius or a historian to observe that while the older generations do not have this "problem" (they're very skeptical of the gov. [at least in certain aspects], in an almost american fashion — explained by the fact that they've experienced communism), younger generations position themselves in the extreme opposite; they despise the older generations ("boomers") for being luddites and somehow blame them for the gap in civilizational progress between WE and EE. There is a legitimate point here, of course, but it should be noted that the argument is almost always presented in an emotional, overwhelmingly irrational fashion, and almost never includes comparisons between the centralization done by the state in the past [communists] and the new one attempted by current govs [but digitalized]. (This delves into a broader socio-cultural divide between the generations that includes other aspects like religion, traditions, etc.)
The biggest portion of the so-called "IT people" who call for this "digitalization wave" are midwits, "inverse luddites" (they don't care about the implications), and, in smaller numbers, grifters and second-order beneficiaries (on the "digitalization" gov. projects). Obviously, it should be mentioned that, despite progress, nepotism and corruption are still present, and there are cases where gov. contracts are not given to the best candidate.
As a person who's both working in the IT sector and not a boomer (despite the impression of my comment), "we" should be careful about enabling totalitarians in our endeavors."Hackers" is just one reason out of a multitude of other reasons for not abandoning the sacred paper (see the ES+PT incident one year ago).
The last thing any government will want to deal with is massive irretrievable data loss.
I had a copy of our code on media in my desk labeled “promotion” and updated it every month. In retrospect someone going through my desk would have assumed blackmail material and been disappointed to find only code.
So they rebuilt it first from first hand proof, then by testimonies, with a period of counter claims available IIRC. For sure there were some false claims, but given the magnitude of the disaster, this is the best solution within that context.
/joking, i'm sure this is not a happy time for whoever is trying to rebuild everything
If the hacker was targeting the erasure of a particular recent transaction, they may well have succeeded. And by deleting numerous others, they have plausible deniability in the subsequent dispute over the property. If you just wipe a record that is related to you, and the manipulation is discovered (which it will be, one way or another), you are part of a narrow circle of suspects.
The dumb thing was the bank was two blocks from the data center and less than eight (six?) from the office so catastrophic events might have hit both or all three. The owner kept a second copy at his house, and that was the only geographically separated copy.
It's even more funny on Reddit when you can see the person who is blaming cronies in his Romania but has posts of him doing some blue-collar work in the Midwest.
Moving from a paper registry at each county clerk (in the US) was a part of the 2008 financial meltdown.
> backup the attacker can reach is not a backup
you can have append-only backup systems.A close relative, government employee, was in charge of building a new application. They have nobody in that entire organization of several thousands people that know how to write specifications for an IT application, nobody that knows how to design, test and deploy it. This is because some government employees have decent salaries, but in IT the private sector is paying a lot more, so almost anyone remotely competent is going to the private sector. So in this case an organization of non-IT people had to deal with the contract and all the associated problems - there is no need to guess, it did not go well. That kind of project could have been done properly with ~ 10% of the budget in the same timeline.
I have a friend that worked as a developer in such a government IT project. The project cost was ~ 5-10 times what was worth, a chain of sub-contractors did the work, less than ten competent people doing the project, charged by the bid winner for over 100 people and actual staff was around 70 at most, for a short period of time.
Both projects above are in Romania. Lack of competent people in the projects, especially in decision roles, was the main problem.
Blizzard gave hardware tokens out to the entire convention one year. Smart phones became a variable not long after and then they didn’t make them mandatory but game guilds almost universally did. Especially for officers.
> Sources told Risky Business that the hacker entered using valid credentials
Permissions inside the database should be segregated. The credential used by the webserver should not have enough permissions to DROP DATABASE. Just the appropriate selects/updates/inserts.
Likewise, if you are storing backups on the same network (as opposed to a tape backup), network permissions should allow writes/creates but not deletes.
This proclamation, coming from a governmental organization, makes me afraid they are doomed. Effectively they are saying they are fixing the mistake by repeating it.
What they should do is admit fault. Freeze the system. Get independent expert help.
Best wishes, recent Romanian land buyers and sellers
Edit: thank you @cbg0 for giving us this update
It is a poor idea to use blockchain for government registries. If you want transparency, simply publish signed daily updates and that's enough. Just use simple DB with backups, and optionally, a printer printing changes on a paper.
What's wrong with paper records backup up a digital record and audit trail. This all seems like a solution for a non-problem to me.
Blockchain doesn't have anything esp. to do with data loss. It solves exactly one problem which is distributed double spending in accounting ledgers.
You know, it's not like people would come and steal your land overnight because you can't provide proof of ownership.
Like whenever someone gets caught in a compromising situation they say they "were hacked", as if saying that means anything.
In this case I expect an underpaid employee, and at most an incompetent nephew of someone. They had no reason to have an .authorized_keys file in the webroot of the website, and yet they did.
If you want to know what "dedicated contracts" look like in practice they are overly specific requirements than can only match a single business. The best example that comes to mind was when one county needed to buy busses (or vans) and the maximum length admitted was bellow the most common options, but as luck would have it a nephew of a cousing of someone with decision power (or something like that) just so happened to be the one importing cars that precisely matched the specs.
The whole country's real estate market was paralyzed for about a month. It took couple of months to restore everything from backups and paper agenda and resume normal operation of the land register office.
It was the largest cyber attack in Slovakia's history. The authorities to this day haven't provided any information on who might be behind it. The investigation is still ongoing. Several government figures including the PM were however very eager to immediately point on Ukraine, without any sort of proof.
It did help the West, and especially the UK, to get as immigrants very high good plumbers and handy men. The rest of us went into STEM and are now working for FAANGS.
All you need is an append only tape or even a printer.
Interestingly in the Bangladesh Central Bank hack they used a printer to print out any transactions, but the intruders disabled it or it was just malfunctioning because it's a printer.
But I doubt the Romanians actually had such a system.
"1T+ in assets are frozen as Slovakia's Land Registry faces ransomware attack" <https://spectator.sme.sk/politics-and-society/c/news-digest-...> (9 Jan 2025) HN discussion (1 comment): <https://news.ycombinator.com/item?id=42650343>
"Ransomware Attack Paralyzes Slovakian Land Registry, Souring Slovakia-Ukraine Relations" <https://dailysecurityreview.com/security-spotlight/slovakian...> (January 14, 2025)
"Slovakia Hit by Historic Cyber-Attack on Land Registry " <https://www.infosecurity-magazine.com/news/slovakia-hit-by-l...> (10 January 2025)
Apparently tied to Ukraine in this case.
Also, you still have paper documents, kept by parties to transaction, right?
Plus having most of your net worth locked up in something no sane person would consider buying off you because you can't prove you own it is ... suboptimal
At the same time they are working with authorities.
Not everything needs an external consultant.
- We have 2 sources of data that we must backup to continue existing as a business; our postgres and binary files in S3. Everything else is derivable (elasticsearch, so on).
- For postgres, we use barman. With the help of opus/fable, you can get a streaming replication backup working in no time. We have one into another server in the same datacenter (we use baremetal) and another one in another server in a different datacenter.
- We then have a last resort barman backup with bi-weekly base backups + WAL streaming to S3 (both the base backup and WALs). It sends these backups + wal segments into an specific S3 bucket that has object lock in compliance mode. This is a feature from AWS S3 that even the most privileged account credentials (super admin) can't turn off nor delete the files before the object lock, which is 10 days in our case. Object lock compliance mode can only be extended, never shortened.
- For S3, we store them into another versioned bucket, with lifecycle rules to also expire non current versions (== deleted objects) after 10 days. No point in object lock compliance here because it would only protect objects for the most recent 10 days, and you gain nothing. What we do instead: the app servers only have access to these bucket tru an IAM credential that can't delete old versions (so deleted objects have to expire manually via the lifecycle rule) AND this IAM credentials also can't change the object policy.
IMHO, this protects us enough so that even in the worst case scenario (ransomware) we have 10 days to sort everything out and recover our AWS access.
And yes, we test the S3 barman restoration and it works fine. Data loss is at max 5 minutes due to the archive_timeout=300s on the primary.
For the streaming replications in the two servers I mentioned, it's less <1ms, but those wouldn't protect us much in the case of the ransomware - even tough we use tailscale and one compromised server can't ssh into the other.
Here is one I learned recently - govt started issuing birth certificates online. Hopefully Less corruption, right? Officials made deliberate spelling mistakes in names etc, because you have to go in person for corrections. In person means bribe, which means back to same situation as before (almost)
Possibly since 1086
So all is not lost if the registry goes up in flames.
Just recently I've seen a 30 y.o. deed on some commercial property. Despite it was valid and predated the digital era, it had almost nothing common with the things on the ground.
A great-great grandfather of mine was mayor of a town through which the front passed twice during WWI. All that survived were basements. Your father's account more or less describes the process by which the land was reparceled.
Property that isn't registered can remain unregistered but must be registered before it is sold.
A blockchain is essentially that, just with the daily update that's being signed also including the signature and hash of the previous day.
Blockchain as a technology is actually useful here. It does not mean automatically that blocks have to be mined by third parties, although pseudocurrencies have gone that route for decentralization reasons.
Why does full access include the ability to delete read only data that should never ever be deleted for the rest of time?
It's like building a self destruct button that ignites the physical records. It's an unnecessary risk to make such a dangerous thing.
Now you may argue "that is a blockchain, not every blockchain is associated with a shitcoin" but to be frank that ship has sailed, if you wanted to defend that you'd have had to do a lot more work over the past decade.
> Sources told Risky Business that the hacker entered using valid credentials
This is social engineering or corruption.
In a similar vein, I was once curious how you would prove your identity if ALL of your relevant documents (passport, driver's license, birth certificate etc) were lost in some kind of cataclysm e.g. a house fire pre-digital etc
Turns out there is actually a mechanism for this:
- get multiple people to sign sworn affidavits that you are who you say you are
- that begins the "paper trail" of evidence that allows you to start getting the rest of the document chain
- you rebuild from there.
If you're married, there is already a similar process for when a spouse takes the last name of the other spouse. The marriage certificate is the first step and then it goes from there for driver's license, passport, credit cards and so on.
When you buy property you get a deed for the land, but the details of a property can change after that. The deed also doesn't contain ownership, it just says what is on the land. It's common for land to have multiple owners (1/32 is not unheard of) due to inheritance.
I'm building a house, the land deed just has the land plot as we bought it, until the house is 100% finished (and registered) we will not get an updated deed, although the digital system has newer data (you need to register the construction progress).
Lord no! That accusation doesn't pass the sniff test.
Try looking further east for the real culprits.
The amount of times my SSN and correlated info has been leaked and I've been offered a free year or credit monitoring is depressing.
mirror that DB onto a server on the other side of the country, or continent, etc.
This newsletter is brought to you by Thinkst, the makers of the much-loved Thinkst Canary. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.
A hacker has breached Romania's cadastre agency and wiped the country's entire land registry database following a failed extortion attempt.
The hack has brought Romania's entire real-estate market to a standstill as official apps and websites have been offline for a week. Notaries can't record new transactions while citizens can't obtain proof of ownership or detailed land records.
Email servers at the National Agency for Cadastre and Real Estate Advertising (Agenția Națională de Cadastru și Publicitate Imobiliară, or ANCPI) were also down as part of the incident.
Sources told Risky Business that the hacker entered using valid credentials, mapped internal systems, and wiped systems and backups after failing to extort the agency.
The incident became public on July 14 as the hacker started deleting data. A day later, some of ANCPI's stolen data was put up for sale on a known hacking forum. The posted data included employee credentials, internal documents, and details on the agency's IT network.
Since the hack, officials restored their website and posted a message announcing they are rebuilding the agency's entire network from scratch. Even if the hacker claims they deleted backups, the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months in Romania.
The stolen data was posted online by an account with the name ByteToBreach, a known hacker who also breached Sweden's e-government portal this year, and many other government agencies and high-profile companies over the past year.
Security firm KELA published a profile on ByteToBreach last December and hinted they might be located in Algeria, but since the ANCPI hack has updated the post and outright doxxed the hacker as Zakaria Mahdjoub, an individual from Oran, Algeria.
Well, that will make the job of Romanian law enforcement a hell lot easier! gj!
Romania joins Poland, Slovakia, Greece, Morocco, Russia, and Ukraine as countries that had their land registry agencies hacked over the past three years.
In this edition of Seriously Risky Business, Tom Uren and James Wilson talk about different ways ransomware groups are taking advantage of AI. The relatively new FulcrumSec group uses simple techniques to breach companies and then uses AI to get more leverage over victims in its extortion negotiations.
Hugging Face hacked using AI: A threat actor used an autonomous AI agent to breach AI platform Hugging Face last week. The attacker used exploits in the platform's data-processing pipeline to pivot to some parts of the company's internal systems. Hugging Face says no customer data was exposed but the attacker stole internal datasets and some cloud credentials. Hugging Face says it tried to use a frontier AI model to analyze the hack but was blocked by its guardrails, which couldn't differentiate between an IR event and offensive operations. [Hugging Face]
HuggingFace got hacked by an AI. What stuck out to me was the guardrail asymmetry. The attacker had no constraints, but HF's response ran afoul of the abuse guardrails, forcing them into an unplanned switch to local models. Another aspect for your IR plans. huggingface.co/blog/securit...
— David J. Bianco (@davidjbianco.bsky.social) July 17, 2026 at 10:59 PM
Coca-Cola hit by ransomware: Coca-Cola has suspended production at its Fairlife dairy subsidiary after a ransomware attack. In an SEC filing, Coca-Cola said hackers accessed Fairlife production-related systems this week. Production has been halted at Fairlife US factories. The company's Canadian production lines were unaffected. No ransomware group has taken credit for the incident, yet. [SEC // TechCrunch]
Qantas breach has a cause: The hack of Australian airline company Qantas last year was traced back to a social engineering attack. Hackers called an overseas contractor posing as the Qantas IT team to access their systems, connect to the Qantas CRM platform, and exfiltrate the data of 5.7 million customers. Australia's Information Commissioner says Qantas took all the steps to protect customer data on its side and will not be opening further probes into the hack. [OAIC]
Suno hack: A threat actor hacked AI music generator platform Suno and dumped internal files and documents online. The files allegedly show that Suno scraped millions of songs and lyrics from YouTube Music, Deezer, Genius, and other music platforms. The leaked files include source code and detailed scraping instructions targeting the platforms. Several music industry groups have sued Suno over the past year for training its AI song generator tool on copyrighted material. Suno was allegedly hacked following a compromise with the Shai-Hulud npm worm. [404 Media // The Verge]
WINDTRE fined for breaches: Italy's privacy watchdog has fined telecommunications provider WINDTRE €1.7 million for "serious security deficiencies" that led to two security breaches last year. [GPDP]
KNPP leak: Threat intel analyst Rakesh Krishnan looks at a leak of sensitive files from India's KNPP nuclear power plant after one of its contractors got hit by the World Leaks extortion group. [The Raven File]
Ostium crypto-heist: The Ostium DeFi platform was hacked for $18 million last week after hackers exploited its own price-reporting infrastructure. [CoinDesk]
Estée Lauder discloses Oracle EBS breach: Cosmetics giant Estée Lauder has confirmed that hackers stole customer data from its Oracle E-Business Suite platform last year. The company disclosed the breach to US state officials almost a year after it took place. This is Estée's second breach after another one in 2023. The Clop hacking group is behind the hacking spree that targeted Oracle EBS servers. [California OAG]
Ernst & Young also discloses breach: Accounting and risk management giant Ernst & Young also disclosed a breach, but the disclosure has been so sanitized of any info that I can't tell what's this about. [California OAG]
DigiCert breach linked to CylindricalCanine: Security firm Expel has linked the hack of certificate authority DigiCert to CylindricalCanine, a sub-group of GoldenEyeDog, a financially motivated group operating out of China. [Expel]
Ofcom opens TikTok inquiry: The UK's communications watchdog has opened a formal investigation into TikTok for failing to protect children from harmful content on the platform, as per the UK's Online Safety Act. [Ofcom]
Moonshot releases Kimi K3: Chinese AI startup Moonshot has unveiled a new AI model named Kimi K3, which the company claims can rival the ones from top American firms like Anthropic and OpenAI. [Kimi // Business Insider]
Rust in Chromium: Microsoft is working on adding a Rust-based PNG image decoder in the Chromium browser project, a more secure component for processing PNG images for Chrome, Edge, Opera, and other similar browsers. [Microsoft]
EU password manager has ties to Russia: An investigation has revealed that Spain-based password manager Passwork shares its codebase and a "near-identical user manual" with a similarly-named password manager advertised in Russia. The Spanish version has allegedly been receiving software updates from an UAE firm managed by one of Passwork's Russian co-founders. The Spanish Passwork's customer list includes European government agencies and universities, which raises concerns of espionage. [OCCRP]
India fines HP over cartel practices: The Indian government fined HP $14.4 million over cartel practices after the company colluded with resellers to fix prices for ink cartridges, toner, and other printing supplies in government contract bids. [ArsTechnica]
SanFran CAO cracks down on nudify apps: The San Francisco City Attorney's Office has sent cease-and-desist letters to Apple and Google and ordered the tech giants to remove AI nudify apps from their stores and stop indirectly profiting from CSAM. [WIRED]

Morocco confirmed as NSO customer: A whistleblower and former member of Morocco’s domestic intelligence service has confirmed their government's access to the NSO Pegasus spyware, contrary to the government's past public denials. The tool was heavily used to spy on dissidents, journalists, and even politicians abroad. [OCCRP // Forbidden Stories]
UK scraps digital ID scheme: The UK government will scrap a proposed digital ID scheme once its new prime minister Andy Burnham takes office on Monday. The scheme was announced last September and was supposed to enter into effect next year. It involved issuing a digital ID for UK citizens and legal residents in the form of a mobile app. The ID was meant to serve as proof for the Right to Work in the UK. [Reuters]
US govt fails to rotate cyber personnel: The US government failed to follow through with one of its own programs to rotate cybersecurity employees between federal agencies. Only eight employees participated in the program since 2022. The program was meant to teach employees new skills before returning to their native agencies. [GAO // Cyberscoop]
White House announces Gold Eagle program: The Trump administration has launched a new program to help coordinate the disclosure and patching of vulnerabilities in open-source projects and critical infrastructure. The new Gold Eagle program was designed to receive bug reports at scale, usually found using AI tools and frontier AI models. CISA, the Treasury Department, and the Pentagon are involved in the program. [White House]
France bans Polymarket: The French government has ordered internet service providers to block access to prediction market betting platform Polymarket. The French regulatory authority formally banned the platform in 2024 and threatened fines of up to €200,000 for French citizens placing bets on the platform. The agency moved into active enforcement after data showed Polymarket's userbase grew in France despite the ban. Spain also banned Polymarket in May. [Engadget]
In this Risky Business sponsor interview, Casey Ellis chats with Haroon Meer from Thinkst about building companies customers don’t hate. Haroon explains why Thinkst still offers Canary tokens for free and why it has avoided annual price hikes on its paid products. They talk about Eric Ries’s “Incorruptible”, Rob Lee’s 100-year-company approach at Dragos, and why keeping customers happy is a better business strategy than chasing easy sugar highs.
Graykey maker sues employee for leaking exploit: Graykey-maker Magnet Forensics has sued a former employee for allegedly leaking details about a proprietary iPhone exploit. Magnet claims Mario Del Gaudio shared details of the exploit with his new employer and rival company Paradigm Shift. The exploit was tracked internally at Magnet as MSG but was disclosed publicly by Paradigm Shift in a blog post as usbliter8. The exploit allows attackers to run malicious code inside the SecureROM of Apple devices using A12 and A13 chips. It is a hardware bug and unpatchable. [Bloomberg // CourtListener // usbliter8 blog post]
TfL hackers get five years: A UK judge has sentenced two members of the Scattered Spider hacking group to 5.5 years in prison each. Thalha Jubair and Owen Flowers pleaded guilty last month to hacking the London public transport authority in August of 2024. The hack caused months of disruptions at Transport for London and caused damages of £39 million. Jubair is also charged in the US with hacking and extorting 47 US companies and allegedly seeking ransoms of at least $115 million. [NCA]
REvil hacker arrested in Armenia: Armenian authorities have arrested a suspected member of the REvil ransomware group. Alexander Ermakov was arrested at the Yerevan airport at the end of June on an Interpol arrest warrant. A man named Alexander Ermakov is the main suspect behind the ransomware attack on Australia's Medibank insurer in 2022. Russian media claims that Armenian authorities arrested a man with the same name and that the real Ermakov is in Russia, where he is serving a restriction of freedom sentence that prevents him from traveling abroad. [RIA Novosti // Risky Business]
Scam center dismantled in Timor-Leste: Police in Timor-Leste have raided three cyber scam compounds in the capital city of Dili. Police arrested 253 suspects, with most being Chinese and Indonesian nationals. Authorities also raided another compound last month. [ABC]
DHS seizes 30,000 mobile SIM cards: The DHS Homeland Security Investigations seized more than 30,000 mobile SIM cards in June and July as part of a crackdown against telephone fraud. [Bloomberg]
GTA hacker released from hospital, sent to prison: A member of the Lapsus$ hacking group has been released from a secure hospital and transferred to a normal prison in the UK. Arion Kurtaj is set to face trial again for hacking Rockstar Games in 2022 and releasing GTA5 source code and GTA6 gameplay. Kurtaj was diagnosed with severe autism and sentenced to an indefinite hospital order in December 2023. [GameRant // Polygon]
UAT-11795 profile: Cisco is tracking a new e-crime group targeting companies in the US and Europe with the Starland RAT and a command-and-control (C2) memory implant named the WLDR Agent. [Cisco Talos]
TAG-150 evolution: eSentire has published details on the changes to the tradecraft of TAG-150, an e-crime group behind the CastleLoader, CastleBot, and CastleRAT malware strains—also tracked as DinDoor, a Deno-based loader, NightshadeC2, and DenoRAT, a Deno-based Remote Access Trojan (RAT). The biggest change is their adoption of ClickFix, everyone's favorite infection vector. [eSentire]
More ViPNeT exploitation in Russia: A hacking group is planting backdoors inside Russian companies using the ViPNet enterprise VPN software. The attackers first compromise one VPN node and then exploit the software's update mechanism to install the backdoor on the whole network. ViPNet owner Infotecs has confirmed the attacks and released security updates. A similar wave of attacks also took place in April last year. [Infotecs // PositiveTechnologies // Kaspersky // Last year's attacks]
Scarcity scams are here to stay: Scarcity scams are a new category of online scams where threat actors run fake sites for online services with limited availability or spots. This type of scam has exploded across the past few years and typically target the reservation sites of various government websites across the world. [DomainTools]
Sextortion campaigns: A recent spike in sextortion email scams has been linked to the good ol' Trik/Phorpiex botnet, which is still alive after all these years. [PointWild]
Text salting in the wild: Threat actors are using a technique named "text salting" to hide text inside their emails and bypass email spam filters for both traditional and AI-powered email security systems. Barracuda has seen the technique used in over a million retail-themed phishing scams. [Barracuda]
RubyGems malware: At least two dormant RubyGems accounts have been compromised to push malware to old projects. [Aikido Security // Step Security]
OAuth Client ID Spoofing: Threat actors are using OAuth client ID spoofing to abuse Microsoft Entra ID for account enumeration, check password validity, and account state. The technique is seeing increased usage, per Proofpoint. [Proofpoint]
Proofpoint observed two independent campaigns adopting this tradecraft: • UNK_PyReq2323: >1M targeted users, 700K+ spoofed client IDs • UNK_OutFlareAZ: >2M targeted users, 3.7M spoofed client IDs Different tooling and infrastructure suggest growing adoption.
— ThreatInsight (@threatinsight.proofpoint.com) July 14, 2026 at 6:56 PM
XZ Utils backdoor: Adrian Mastronardi has published a book with the in-depth story of the XZ Utils backdoor incident from 2024. [Half a Second]
Pegasus spyware: The security team at Amnesty International has published the most comprehensive analysis of the Pegasus spyware to date, leveraging the insights from past reports and the recent WhatsApp lawsuit. [Amnesty International]
ClickLock Stealer: A new infostealer targeting macOS users has been spotted in the wild. This one has been named ClickLock because it blends ClickFix and locker tactics for its distribution and installation process. [Group-IB]
CrashStealer: There's also another macOS infostealer in the wild, named CrashStealer because it tries to impersonate Apple's crash-reporting framework to harvest browser credentials, cryptocurrency wallets, and keychain data. [Jamf]
ACR Stealer: Microsoft has reported an increase in attacks deploying the ACR Stealer across customer environments since April. [Microsoft]
BoryptGrab: Almost 300 GitHub repositories impersonating legitimate software were actually spreading a version of the BoryptGrab infostealer. [Arctic Wolf]
TELEPUZ: Elastic has spotted a new malware framework being deployed in the wild that appears to be related to an upcoming MaaS. [Elastic]
Spirals ransomware: Broadcom's Symantec team has spotted a new ransomware strain named Spirals being deployed in Asia. Not much information about it so far. [Broadcom]
NadMesh botnet: A newly discovered botnet is specifically targeting AI infrastructure and the MCP ecosystem. The NadMesh botnet has targeted Ollama, ComfyUI, and other AI-related servers since early July. The botnet plants SSH backdoors for control and future access. According to Chinese security firm QiAnXin, the botnet appears to be an "industrial-grade" operation with a "clear commercial intent." [QiAnXin]
OkoBot framework: Researchers have found a new modular malware framework named OkoBot that resembles an infostealer but puts more focus on stealing sensitive data from cryptocurrency owners and related services. [Kaspersky]
"The OkoBot campaign has been ongoing for over a year, and it remains active at the time of publication. Moreover, it is adapting, which indicates that this framework is being maintained and distribution campaigns continue."
WackoGinx phishing kit: Researchers have found a new phishing kit named WackoGinx (also WachoGinx) that can run campaigns targeting M365, Facebook, Gmail, LinkedIn, and PayPal. [Threatactix]

In this Soap Box edition of the podcast, Patrick Gray chats with Thinkst Canary founder Haroon Meer about his "decade of deception."
UTA0533 is behind new SonicWall zero-day wave: A hacking group tracked as UTA0533 is behind two zero-days exploited in SonicWall SMA appliances. The zero-days include an SSRF and a code injection vulnerability that grant the group root-level access to the device. The attacks began in late June and are deploying malware designed specifically for SonicWall SMA VPN appliances. SonicWall released patches for both zero-days last week. [Volexity // SonicWall patches]
GoSerpent campaign: Kaspersky is tracking a new APT group deploying the GoSerpent backdoor, Stowaway, and TmcLoader in campaigns targeting government and diplomatic entities in Southeast Asia. No attribution yet. [Kaspersky]
Laundry Bear member worked at Kaspersky: Denis Obrezko, the Russian national who was arrested in Thailand last year, extradited to the US, and charged with hacks part of the Laundry Bear APT group, also worked for Russian security firm Kaspersky. A team of threat intel analysts going by Ctrl-Alt-Intel has also published a profile on Obrezko and the opsec mistakes that led to his arrest, which is well worth your read. [Reuters // Ctrl-Alt-Intel]
Love that a leaked McDonald’s order helped corroborate the attribution 😂 Great pivots! https://t.co/XZUeBAWZYZ
— Chi-en (Ashley) Shen (@ashl3y-shen.bsky.social) (@ashl3y_shen) July 14, 2026
Sandworm adopts ClickFix: Even if they're one of Russia's most advanced cyber-espionage groups, Sandworm is now using ClickFix for malware delivery. [CERT-UA]
More DPRK on npm: OSM's Jenn Gile has linked two clusters of npm malware back to North Korean hackers and their PolinRider campaign. [OpenSourceMalware]
Operation Capsule Vault: And speaking of DPRK hacking campaigns, there's one spreading the RokRAT malware using edu- and academic-related phishing lures. [Genians]
Contagious Interview campaign: There's nothing more dangerous right now than trying to find a job in the IT sector, thanks to North Korean hackers! Putting the irony aside, there's a new report on the Contagious Interview campaign that Elastic tracks as REF9403 activity. The report covers the use of SVG files to hide malicious commands via steganography, which is kind of original in its own specific way because SVG files haven't been broadly abused for steganography until now. [Elastic]

wp2shell vulnerability: The WordPress team has released a security update to patch one of the most critical bugs ever found in the project's code. The vulnerability is an SQL injection in the WordPress REST API that can be exploited by remote unauthenticated attackers to run malicious code on any WordPress site. The issue can be exploited without any preconditions and impacts all WordPress versions released since last December. WordPress sites power more than 41% of all internet sites. The bug was discovered by Searchlight Cyber and is tracked as CVE-2026-63030, or wp2shell. [Searchlight Cyber // wp2shell // WordPress patch]

HollowByte attack: A new vulnerability can crash OpenSSL servers using only an 11 bytes payload. The attack can be exploited by remote unauthenticated attackers and force servers to allocate huge amounts of memory before any secure TLS handshake even begins. The OpenSSL project released patches for both current and old library versions last month. The vulnerability was discovered by Okta and is named HollowByte. [Okta]
Android lockscreen bypass: Just like Siri has been exploited for years to bypass the lockscreen, it's now Gemini's turn to be abused to bypass the Android lockscreen. [Android Headlines]
Vulnerability disclosure guide: CISA and international partners have released joint guidance on establishing proper coordinated disclosure programs. [CISA]
Nightmare Eclipse drops LegacyHive: Security researcher Nightmare Eclipse has released a new Windows exploit last week. Named LegacyHive, the zero-day is a local privilege escalation in the Windows User Profile Service. [Project Nightcrawler // GitHub // SecurityWeek]
AoE RCE: The last thing you ever expected is probably a remote code execution exploit in the good ol' Age of Empires game.
Here’s the Age of Empires RCE from yesterday’s Patch Tuesday: CVE-2026-50663.
Join an attacker’s lobby, (auto-)accept UCG, and you get remote code execution. pic.twitter.com/QmMkY07C8S
— Rick de Jager (@rdjgr) July 15, 2026
Threat/trend reports: Acronis, CompariTech, Moonlock, ReliaQuest, Sonatype, Sophos, Thales, and WatchGuard have recently published reports and summaries covering various threats and infosec industry trends.
BSides Budapest 2026 videos: Talks from the BSides Budapest 2026 security conference, which took place in April, are available on YouTube.
In this edition of Between Two Nerds, Tom Uren and The Grugq discuss just how important exploits are for cyber operations using data published in a new paper authored by two members of Ukraine’s cyber security agency.
In this episode of Risky Business Features, James Wilson chats with SOCRadar CISO Ensar Seker and James Wilson chat about the company’s deep dive into the Fortibleed campaign. A small investigation into a curiously open directory on an unknown server expanded into the discovery of an attack that targeted 400,000 Fortinet devices.
If you've specific information clearing or establishing the link, post it. I agree that hasty accusations are risky. The main point I was looking to establish was that the source wasn't indicated as Algerian, as with the Romanian incident.
Also, SQL database is much more convenient to use, it has query language and indices unlike a blockchain.
It's not. Blockchains are only eventually consistent among nodes. They're designed for synced backups among adversarial peers.
There's no reason for a government agency to use one internally. There are better ways to sync backups when the people with access to make updates are also authorized to do so.
The intent of abolishing private property would presumably be the latter.
What do you mean by "More Work" here?
There were plenty of tests and pilots of systems like that described. Dual goals of reducing the cost of transferring property and publicly attesting all current ownership. Real lawyers and real lawmakers developed proposals to integrate these sort of services with current public land registries.
The issue as far as I see it isnt the "work" its the "antiwork". If you want to learn about land sale nft pilots you literally have to put -metaverse into the google search to weed out the metaverse nonsense. Theres just too much noise around blockchain for even the best signal to penetrate. The stupid monkey nft guys really fucked the whole space. Probably take another decade to dig out all the toxic waste from blockchains reputation.
In Brazil the books are append-only, they have the whole history of thay piece of land since records began. If it was a bigger plot that was dismembered, it is there too. When ownership changes you have to register the contract/terms of transfer/sale separately in a different process, but that does not change legal ownership and you still must go to the registry and register that registered transfer/sale in the registry, and the paperwork you get is a new certificate of registration which is a new snapshot of the books and includes that whole history from the very beginning. There is no copy or certificate you can can get from the land registry without including that whole history.
That's... a curious thing to have in the body of laws. What's its purpose and who does it serve?
Registration is now compulsory on sales, but that only came in in 1990.
As to what I mean by binned, I mean literally binned, thrown away.
Of course, if you fall into a crack that is beyond their reach you will almost certainly have a more difficult time. For a variety of historical reasons, there has been relatively little reliable documentation of American citizenship so the system adapted to that reality.
Corruption and oppression are signaling and coordination problems. The illegitimate sovereign is exploiting informational assymmetry: they know your neighbors are just as angry as you, they know it because all the walls have ears.
They need to prevent you and your neighbors all knowing it at the same time. Your best play is to find some signal, something difficult to censure, hard for the goons to pick out in a crowd but legible to your neighbors. If you all knew that the first guy to shove back when the cop shoves you is going to be followed by a swarm of guys? Very easy to find the first guy in that case.
This is why shit like extremely high gas prices scares the shit out of illegitimate sovereigns: they're the ones posting pure data about why everyone should be that angry right now.
[1] https://community.apryse.com/t/jbig2-compression-issue/1814
[2] https://en.wikipedia.org/wiki/JBIG2#Character_substitution_e...
Everytime I get stuck with some kind of circular bureaucracy I shout "it's Banana Joe all over again!" and no one understands.
Oddly enough, if you legally change your name, they will send you a new one regardless of the limit.
I got my first passport at a formative period of my life (international travel does that). I looked nothing like the photo within aa year. It served as a passport until it expired but only created skeptisism as a photo ID.
I don't know how to drive, so do not possess a driver's licence. I am in a 35+ year relationship, but unmarried.
The only purchase I have made on finance was a bed that I immediately paid off because the the only reason I did it was to establish a record. This was surprisingly difficult to do because they were reluctant to let me have the bed on finance because I had no credit record.
I finally had to renew my passport when I bought a house. It was the only way I could meet the id requirements.
Prior to that I was leveraging non-photo id that could only be acquired with photo-id. It seen that will be accepted in lieu in many instances and allows you to get more similar forms of non-photo ID. All you need to get started is to find a staff member fed up with the ridiculous rules enough to click the checkbox to say that they saw a photo ID. It helps that many of the staff in these positions are more aware of security theater than the general public.
Being a land owner means a lot of those days are peassed, I can't really prove I am the person who is recorded as owning the land, but mostly organisatipns are happy that I am claiming to be someone they know exists.
Linkedin has stopped asking. I'm not sure if that means they think I am a lost cause or that anyone not on their books by now doesn't actually exist.
If stored properly.
So are digital copies, though. If stored properly.
depends on configuration, you can make any traditional web service replicated (replication is one and only thing that protects data in decentralized ledger, same as DNA is stored in every cell) using something like CometBFT on top. Mining/PoS or VM - all optional.
Yes, if you have a centralized model you don't need it. Just saying that this incident is the exact risk a blockchain is meant to mitigate through redundancy. You can say you don't care about this risk, but it doesn't change the truth of the statement.
If they are clearly misusing a system (SSN) never designed nor intended that way. And continue to do so even after being shown the facts.
And now I also know that he has a law degree, has several registered patents, and was a certified airline pilot. Pretty impressive.
Also, this sort of event should result in some hackers being found and jailed for life as well as their families being bankrupted permanently. Or, if they are being protected by their government, this should be considered an act of war and an appropriate military response should be delivered.
"Hold up in court" as in was it duly executed and filed by a certain date, regardless of the time and extra management required for the bank's performance? Yes, why not.
"Hold up in court" against someone claiming it was an unauthorized transfer? Even without the bug, that can be contested in many straightforward ways!
But unless there is a specific legal claim that hinges on the bug being significant, it's pretty irrelevant "in court". I knew about this precisely because the transfer failed to go through due to redundancy - one digit in account numbers is generally a check digit, plus account titles and whatnot.
In general you can always challenge the validity of scanned documents, regardless of known software bugs or not! Just like you can always challenge that a paper document is a forgery. You need a specific argument and some evidence though!
(And obviously has some doc to prove it)
Or did a joke about overbearing mother in laws just go right over my head.
"Oh volcano exploded, his home is under 5 ft of ash."
"Gotcha, mail him the copy"
If the you need to know if the fence is on your property or the neighbor’s, a title or deed won’t help you find that line.
So if the official survey is lost and you need to know where the land you own is, you will need a survey.
It is definitely a good idea to plan in advance and set up a recovery contact: https://support.apple.com/en-us/102641
It is very unlikely that you will be asked, even by a prospective employer, for your actual card, because let's face it: it doesn't even have a photo, or anything but that unique number on it. Anyone trying to authenticate your number should be satisfied if you can give them the correct number.
And just for review: SSNs are not a "national ID" and you're typically not required to divulge it to private parties, and they can make up some other unique ID for you in their database. It's usually just a shortcut for them to do a background or credit check on you. And that's not something for which they would need your physical card.
That being said, I've replaced my card about 3 times now, and it was comparatively difficult this time around. The first time, I did it all through the mail (the process of building up from no ID to get birth certificate from out-of-state, to the SSA card, to the in-state driver license.) and the second time it arrived by mail, no hassle.
But this time around, even though I applied online, I was directed to make an appointment at the field office and physically walk in there, to prove my humanity. I had never been to an SSA Field Office in my life! The experience was very chill, and there were a dozen windows serving people, while about 4 of us waited in the lobby, and I was in-and-out half an hour early. The civil servant was a lady in good spirits who was a military veteran. Big props to them!
No one thinks bills of attainder are a good idea.
The United States on the other hand has a massive title insurance industry, which wouldn't exist if this system was implemented. So you can make random handshake agreements all you'd like and sue over it.
[1] https://www.elra.eu/the-principles-underlying-the-land-regis...
But it's more difficult to imagine that 1000 years from now someone will be able to read from a PCI-E NVME drive if the specs get lost along the way (ignoring for a moment that flash storage most likely won't retain data that long).
"i paid for 30 acres here at $xx rate, and here is the mortgage docs from the bank dated March 19th that I signed, plus their valuation of the property and what went into it"
A survey is little more than marching out into the field and putting at the location where you believe the boundaries to be based on your review of the legal description.
Of course that’s not the end of the discussion as to boundaries for reasons like adverse possession or busted titles but on his own a surveyor is going to tell you basically nothing.
What you need is "pyroclastic event" insurance to cover you for ash and lahar.
/ It cost something like $15/year when I lived in Seattle.
// The macOS spell checker doesn't know "lahar."
I'm curious when this happened. The phrase "but this time around" makes it sound fairly recent. However, my wife had this very procedure required back in the 1990's.
She also had the same experience as you: Very friendly civil servants eager to help, and things were cleared up quickly once she understood the process.
In my state, it's one of the allowed document types for proof of social security number, required to get a real ID drivers license.
https://www.mass.gov/doc/ma-real-id-documents-checklist/down...
A git repo with cryptographically signed commits solves all the same problems without the headache.
That's not what they are, but that's what they've defacto become. I hate it.
Totally agree on accessing NVME example.
ADDED: We also had a bunch of easements and cooperative maintenance agreements that were only partially documented in the deed and mostly done via a handshake. So we got that all squared away in the expensive binder from the lawyer.
- get insurance to cover you for X
- get hit by X
- realise you actually got hit by Y after reading the policy small print (or you really did get hit by X, but your policy only covers you for Y)
Getting something like Volcano Insurance requires some specific foresight, I would be slapping myself on the back if my house was covered in volcanic ash right up to the point when I got on the phone to my insurance company to make a claim.And both storage can be broken, needing reconstruction.
If I were to give you a 70y old book in English vs some 70y tape with data on - which one is easier to read?
In his thesis, this is the reason capitalism cannot work well in Latin America and other nations around the world. He says that registered land ownership is the foundation of capitalism. This is how one can borrow money against your land and invest it to make more capital. Very common for example with farmers in N. America to borrow against their farm, for machines, seeds and fertilizer.
(I am not an economist)
Except for certain industries where the government has a direct interest (banking, healthcare, real estate), I don't think anyone has asked for my SSN in at least a decade. It's not like the old days when you'd fork over your SSN to rent videos at Blockbuster.
Not sure if you're being deliberately obtuse here but this isn't an issue with the cadence of real estate transactions. Real estate ledgers do not need to support HFT.
That's still a massive dependance on "ID" for SS...? Blockbuster tho.. phew it's been a while.
If the medium isn't destroyed, it is directly readable if it's a book, but not necessarily so in digital because hardware and software is needed - just taking care of the original medium isn't enough in digital over centuries.
De Soto is talking about why it "cannot" get started in a place without government controlled land registry.
If your proposal is 'something like git, with a few modifications to make it suitable for this use case', then that's exactly what I'm proposing. What you will need, once you've considered all requirements to the best extent feasible, will be a blockchain. Eg you do need the ability to make protocol updates, no matter the time scale of transactions.
De Soto describes the exact opposite situation. Latin America inherited Napoleonic property law, which only recognized property ownership when formally registered, which required quite alot of red tape. It was impossible to transfer ownership without registration. Moreover, any defect in prior registration meant the lawful owner might be the heirs of someone generations ago. Most property "owned" by the peasantry usually had defective and incurable title, having changed hands in informal private agreements, which meant banks wouldn't accept it to secure a loan. This meant only the aristocracy could leverage the financial system, because they were accustomed to following all the formalities. What piece of real property someone thought they owned, even if occupied for generations, was often in the eyes of the law owned by some aristocratic family or the state.
He contrasted that system with the American common law system, where title could be legally transfered entirely privately. Disputes are handled by courts which look to the timing and substance of transfers. Moreover, adverse possession meant that after a number of years (well within one person's lifespan) nobody could come along and claim title because of a defective transfer (even if in principle they had a better claim originally), securing title in whomever held it, even if it had been transferred without even following the much looser requirements under the common law. A bank would issue a loan so long as you could prove you held an unchallenged title for a sufficient number of years. ("Title" was whatever piece of paper handed you by the previous possessors; no government stamp or recordation required.)
Registration systems in the US are a recent occurrence, and they overlay the traditional common law rules.
A gross generalization, but Napoleonic civil law systems emphasize formal transactions centrally administered by the state, while the common law emphasizes looking to the substance of private transactions, and usually only when a dispute arises (otherwise you just presume they're valid). Broadly speaking, De Soto argued the latter tended to favor the common man, because it was much less rigid.
De Soto also pointed out that US Federal Land Grants also did a decent job at distributing land among the people, unlike Latin America where mostly only the aristocracy held land under a good title.
"Cannot work well" and "cannot get started" are two different things. The whole of Latin America apart from Cuba is capitalist, for better or worse, regardless of how bad those countries keep their books.
Firstly, git does not use MD5. It uses SHA1.
Secondly, since 2017 git has shipped with an implementation of SHA1 (sha1dc) that detects the collision attack you describe, which for this use case renders it a non-issue.
Thirdly, git supports `git init --object-format=sha256` which removes the whole issue for anyone who cares to do so.
I think git as-is solves the problem nicely. The only additional value blockchain provides is the ability for someone to point at it and say "look! A use for blockchain exists!" which isn't worth the downsides it'll bring.
And yes I can see that we are at the end of an era. This may be more the end of the U.S. empire than the elimination of capitalism, but for sure a new 'ism" is going to be required soon. What that is will be interesting to see. It would be nice to see someone with imagination come along instead the bipolar options we are handed today.