Loading summary
A
A hacker breached Hungary's state Treasury. Russia will mandate 40 apps on all smartphones next year. Hackers steal Lichtenstein's business database and an AI agent got real CVEs for hallucinated vulnerability reports. This is the Risky bulletin prepared by Catalyn Kimpanu and read by me, Claire aird. Today is the 5th of August and this podcast episode is brought to you by Permeso Security. In today's top story, a hacker has stolen sensitive government data from Hungary's state Treasury. The incident occurred last week. The state treasury says the breach only impacted its Agricultural and Rural Development office. Hungarian officials say no data was lost. A hacker named Byte to Breach was behind the hack. The same individual also wiped Romania's land registry database last month. Meantime, hackers have stolen data from Liechtenstein's business register. The database contains information about the owners of companies in Liechtenstein. There are more than 31,000 businesses registered in the small European country. Hackers have breached more than 200 accounts at the Swiss national IT agency BIT. The intrusion targeted the agency's Microsoft SharePoint servers. BIT says it found no evidence of data exfiltration. The agency manages more than 50,000 workstations for government workers and more than 1,000 government apps. The UK's state investment body exposed sensitive information online for two days due to an employee error. The agency's recent annual report said the personal information of 51 government officials was exposed during the incident. The agency, UK Government Investments, says the staffer did not follow security protocols. At least a dozen US states are responding to Iranian cyber attacks against local water systems. The number of affected states has risen from previous reports of seven. Incidents have now been reported in Clayton County, Georgia and the city of Duchenne, Utah. Last week, Clayton county customers reported low pressure or no water in the middle of the night in Utah. The cyber attack made pumps run dry with while control panels said they were pumping water. The incident also impacted an oil field's wastewater disposal system, but didn't cause environmental damage. Crypto wallet maker Coinkite will stop selling cold card hardware wallets following the discovery of a major bug. Hackers exploited the vulnerability last week to steal $130 million in cryptocurrency. The company has released a patch for the cold card wallets that are already in use. The vulnerability is still being actively explo against users who have not installed the update. Hackers have stolen data from the customer management platform Beacon CRM, which is used by UK charities. Numerous UK charities began notifying donors this week. Affected organisations include the English National Ballet the Centre for Sustainable Energy and the Gardens Trust Beacon serves more than 1,000 charities. The Russian government will require that all smartphones sold in the country are shipped with 40 apps pre installed on them. The apps include the government's official Messenger, Max, the MIA payment app, Kaspersky antivirus, Russia's Play Store, Alternative Rustore, and several Yandex and VK apps. The order comes into effect next year. Meanwhile, Russia's Internet watchdog banned 20 more VPN services this week, bringing the country's total blocklist to around 500 apps services some banned VPN providers reported losing access to their Russian IPs. The government is preparing an allow list of VPN services for business and corporate use. And still with Russia the websites of at least seven major Russian banks were showing errors on Monday after they switched to Russian government issued TLS certificates. Errors were reported on the sites of vtb S, Burbank, Alpha Bank, Rosselk, Hozbank, Promsviaz Bank, Uralsib and the St. Petersburg Bank. The portal switched to using the domestic certificates after their existing certs were revoked by Western cas. The new certificates are not trusted by mainstream browsers. In other news A US House China Committee investigation has found three Chinese telcos have maintained presence on the US market despite an FCC ban. The the report seen by nextgov revealed that China Mobile, China Telecom and China Unicom still have network connections, equipment and data centre space in the us. American lawmakers fear the leftover equipment and connections could be used to hack and spy on U.S. targets. Meantime, the U.S. federal Communications Commission is working on an important ban of Chinese made data centre equipment. The order will primarily target optical transceivers, which are used to transfer data inside data centres. Officials are citing national security as a reason for the ban. The US has already banned the import of various Chinese made routers, drones, robots and solar inverters. The White House says it's finalised a framework for evaluating AI models. The Trump administration set an Aug. 1 deadline for the framework. The White House invited major AI frontier labs to read and test the framework on Tuesday. Officials don't plan to release it publicly. A new worm is spreading across the NPM ecosystem. The initial spread point has been traced back to the Kiwi and Cachable NPM packages, which are both managed by the same developer. The so called chain drop worm has already spread to more than 100 npm libraries. It runs in the BUN runtime, harvests cloud and CI credentials, then spreads to other packages. Hackers have compromised the quickfox VPN app to deploy a backdoor on its users systems. The malware has been active in the Quickfox app since August last year. The app is used by Chinese international students and expats to access gaming servers and websites inside China, according to Fortinet. Open source evidence suggests the China linked Twil Typhoon APT Group may be behind the attack. OpenAI has banned ChatGPT accounts used by a Cambodian scam centre. The centre used the technology to assist with romance, investment and law enforcement impersonation scams. The ChatGPT accounts were also used to craft fake job ads to recruit Indian nationals and lure them to Cambodia. OpenAI says the scam compound operated near the city of Poipett. Chinese authorities have arrested a 31 year old for SMS blasting in Hong Kong. The suspect allegedly drove around the city sending Messages to Phish WhatsApp users for device pairing codes. Once account access was gained, the hackers would demand money from the victim's friends and family. More than half of African cybercrime police cases in the last year involved the use of AI, according to Interpol. AI is now used in all stages of a cyber attack, from reconnaissance to malware development. The agency says there's been a dramatic increase in AI use from previous years, which shows a shift in criminal methodology. Security researchers have found malicious links within 1.7% of AI summaries about major banks and retail brands. These included phishing pages and malware downloads. The test included summaries from ChatGPT, Copilot, Gemini and Perplexity. Perplexity returned the highest number of malicious links. Copilot had the fewest. Software maker Enable has patched an actively exploited zero day, targeting its N Central Remote Management product. Every N Central version is impacted. Attacks were first spotted last Friday. This is the company's second set of patches to address the same issue after the first set didn't work. An AI vulnerability scanner has obtained CVE identifiers for 55 hallucinated bug reports. In most cases, the cited vulnerable code didn't exist, mentioned unrelated functions or the POCs didn't work. One of the hallucinated bugs was an SQLite vulnerability with a severity of 10 out of 10. All the CVE identifiers have since been withdrawn. Microsoft is reducing the lifetime of new new get API Keys from 365 to 30 days. The new change will enter into effect still starting August 17th. On November 1st, Microsoft also intends to invalidate any NuGet API keys created before August 17th. The shorter lifespan is meant to reduce the blast radius of supply chain attacks and finally Samsung will ban smart TV apps that join the company's televisions to residential proxy networks. Samsung becomes the second smart TV maker to ban apps with proxy functionality from their app stores. Research published in June found that more than a third of all LG and Samsung smart TVs were running apps that secretly shared their Internet connection with proxy services. And that is all for this podcast edition. Today's show is brought to you by Promiso Security. Find them@permeso IO. Thanks for your company, Sam.
Podcast: Risky Bulletin by Risky Business Media
Date: August 5, 2026
Host: Claire Aird (prepared by Catalin Cimpanu)
This episode of Risky Bulletin covers the latest cybersecurity news, focusing on a series of significant data breaches and cyber attacks targeting government and private sector organizations worldwide. Main stories include a hacker breaching Hungary's State Treasury, state-mandated apps in Russia, a massive crypto wallet vulnerability, and the impact of AI in cybercrime and vulnerability reporting.
Hungary's State Treasury Hack (00:15)
A hacker known as "Byte to Breach" stole sensitive government data.
The attack affected only the Agricultural and Rural Development office.
Officials claim “no data was lost,” but the scale of compromise remains unclear.
Notably, Byte to Breach is also responsible for wiping Romania’s land registry database last month.
“A hacker named Byte to Breach was behind the hack. The same individual also wiped Romania’s land registry database last month.” (00:34)
Liechtenstein's Business Register Breach (00:41)
Swiss National IT Agency (BIT) Intrusion (01:00)
UK Government Investments Data Exposure (01:24)
At least a dozen US states reported attacks.
Specific incidents in Clayton County, Georgia, and Duchenne, Utah.
Attacks caused water outages; one affected an oil field’s wastewater disposal system but with no environmental damage.
“Clayton county customers reported low pressure or no water... cyber attack made pumps run dry while control panels said they were pumping water.” (02:07)
Coinkite Coldcard Wallet Exploit & Crypto Theft (02:28)
Beacon CRM Breach Affecting UK Charities (02:53)
Russia's Mandatory Apps for Smart Devices (03:20)
All smartphones sold in Russia from next year must ship with 40 pre-installed apps, including government and local alternatives to Western services.
“The Russian government will require all smartphones sold in the country are shipped with 40 apps pre-installed on them.” (03:20)
VPN Service Bans and Web Certificate Problems (03:43, 04:05)
Chinese Telcos Remaining Active in US Market (04:28)
Despite bans, China Mobile, China Telecom, and China Unicom retain infrastructure and presence in the US.
“China Mobile, China Telecom, and China Unicom still have network connections, equipment, and data center space in the US.” (04:35)
US Moves to Ban Chinese-Made Data Center Gear (04:42)
White House AI Evaluation Framework (05:04)
NPM ‘Chain Drop’ Worm (05:20)
Quickfox VPN App Backdoor (Suspected Chinese State-Sponsored) (05:47)
OpenAI Bans Cambodian Scam Center (06:14)
ChatGPT was used for romance and investment scams, as well as fake job ads to lure Indian nationals to Cambodia.
“OpenAI has banned ChatGPT accounts used by a Cambodian scam centre... operated near the city of Poipett.” (06:18)
AI Proliferation in African Cybercrime (06:38)
Malicious Links in AI Content (06:56)
AI Vulnerability Scanner Hallucinations (07:22)
Scanner received CVEs for 55 non-existent “hallucinated” bugs; CVEs have since been withdrawn.
“An AI vulnerability scanner has obtained CVE identifiers for 55 hallucinated bug reports.” (07:22) “One of the hallucinated bugs was an SQLite vulnerability with a severity of 10 out of 10.” (07:33)
Enable Zero-Day in N Central Remote Management (07:09)
Microsoft NuGet API Key Changes (07:47)
On the breadth of international breaches:
“Hackers have breached more than 200 accounts at the Swiss national IT agency BIT... more than 50,000 workstations for government workers.” (01:00)
On AI’s new role in attack methodology:
“AI is now used in all stages of a cyber attack, from reconnaissance to malware development.” (06:51)
On the dangers of hallucinated vulnerabilities:
“An AI vulnerability scanner has obtained CVE identifiers for 55 hallucinated bug reports. In most cases, the cited vulnerable code didn’t exist, mentioned unrelated functions or the POCs didn’t work.” (07:22)
This episode underscores the global and multi-layered nature of today’s cybersecurity landscape: high-profile government systems and supply chain attacks, growing criminal adoption of AI, escalating tech nationalism (especially Russia and China), and the persistent risks posed by human error and rapidly evolving vulnerabilities. Significant attention is paid to how AI is shifting cybercrime tactics—from automated scam campaigns to the confusion of hallucinated security vulnerabilities. The reporting remains brisk, factual, and alert to the broader geopolitical and technological context.