
Loading summary
A
A hacker wipes Romania's entire land registry database Magnet Forensics sues a former employee for leaking an iPhone exploit, an autonomous AI agent hacked Hugging Face and an unauthenticated remote code execution bug was finally found in WordPress. This is the Risky Bulletin prepared by Catalyn Kimpanu and read by me, Claire aird. Today is the 20th of July and this podcast episode is brought to you by Thinxt, the makers of the much loved Thinxt Canary. In today's top story, a hacker has breached and wiped Romania's entire land registry database. Romania's real estate apps and websites have been offline for a week, sources told Risky Business. The hacker gained access using valid credentials and and did not try to extort the agency. The stolen data is now being offered for sale on a known hacking forum. Officials say they're working to rebuild the agency's network. The intrusion was carried out by a hacker known as Byte to Breach, who also targeted Sweden's E Government portal this year. Security firm Keller identified the hacker as Zakaria Majub, an individual based in Algeria. In other news, a threat actor breached AI platform Hugging Face using an autonomous AI agent last week. The attacker used exploits in the platform's data processing pipeline, then pivoted to the company's internal systems. Hugging Face says internal data sets and some cloud credentials were stolen, but customer data was not exposed. Coca Cola has suspended production of its fairlife dairy product lines in the US following a ransomware attack. The company disclosed the incident in an SEC filing this week. The company's Canadian production lines are unaffected. No ransomware group has taken credit for the incident. Yet last year's hack of Australian airline Qantas has been traced back to a social engineering attack. Hackers called an overseas contractor posing as the Qantas IT team to access the Qantas CRM platform and exfiltrate the data of 5.7 million customers. Australia's information commissioner says Qantas took all the correct steps to protect customer data and will not be taking further action. A hacker has breached AI music generator platform Suno and has dumped its internal files and documents online. The files allegedly reveal that Suno scraped millions of songs and lyrics from music platforms including YouTube, Music Deezer and Genius. The files include source code and detailed scraping instructions. Several music industry groups have sued Suno in the last year over training its song generator on copyrighted material. Suno is believed to have been hacked after being compromised with the Shai Hulud NPM worm. Hackers stole customer data from cosmetic giant Estee Lauder's Oracle E business suite platform last year. The company has just disclosed the breach to US State officials almost a year after it occurred. The company also suffered a separate breach in 2023. The clop hacking group targeted Oracle EBS service in a hacking spree last year. The US government plan to rotate cybersecurity employees between federal agencies has failed. Only eight employees participated in the federal Rotational Cyber Workforce program since its launch in 2022. The program was designed to allow employees to develop new skills before returning to their original agencies. The Trump administration has launched a new program to help coordinate the disclosure and patching of vulnerabilities in open source projects and critical infrastructure. The so called Gold Eagle program was designed to receive bug reports at scale using AI tools and frontier AI models. Cisa, the Treasury Department and the Pentagon are involved in the program. And yeah, Gold Eagle. We're confused about the name too. Grey Keymaker Magnet Forensics is suing a former employee for leaking details about a proprietary iPhone exploit. Magnet claims Mario Delgaudio shared details of the exploit with his new employer, rival company Paradigm Shift. The exploit was referred to inside Magnet as msg, but Paradigm Shift disclosed it publicly and as usbliterate. The exploit allows attackers to run malicious code inside the secure ROM of Apple devices with A12 or A13 chips. It's a hardware bug and unpatchable two members of the Scannet Spider hacking group have each been sentenced in the UK to five and a half years in prison. Last month. Tyler Dubair and Owen Flowers both pleaded guilty to hacking the London Public Transport Authority in 2024. The hack caused months of disruptions transport for London and resulted in damages of 39 million pounds. Joubert has also been charged in the US over hacking and extorting 47American companies and seeking ransoms of at least $115 million. Armenian authorities have arrested a suspected member of the Revil ransomware group. Alexander Ermakov was arrested late last month at the Yerevan airport on an Interpol warrant. A man named Alexander Ermakov is also the main suspect behind the ransomware attack on Australia's medibank insurer in 2022. Russian media claims that Armenian authorities have arrested a different man with the same name and the other. Ermakov is in Russia serving a restriction of freedom sentence that prevents him travelling abroad. Three cyberscam compounds have been raided in Timor Leste's capital city, Dili. Police arrested 253 suspects, most whom are Chinese and Indonesian nationals. Authorities also raided a fourth separate compound last month. A member of the Lapsus hacking group has been transferred from a secure hospital to a standard prison in the uk. Arion Kurtaj is awaiting trial for hacking Rockstar Games in 2022. He's also accused of releasing GTA 5 source code and GTA 6 gameplay. Kurtash was diagnosed with autism and and transferred to hospital custody in December 2023. A hacking group is planting backdoors inside Russian companies using the vipnet Enterprise VPN software. The attackers compromise one VPN node before exploiting the software's update mechanism to install the backdoor across entire networks. VIPnet owner Infotex has confirmed the attacks and released security updates. Similar attacks took place in April last year. A hacking group tracked as UTA0533 is behind two zero days that are being exploited in SonicWall SMA appliances. The zero days are an SSRF and a code injection vulnerability. They grant an attacker root level access to the devices. The attacks began in late June and are deploying malware designed specifically for SonicWall SMA VPN appliances. SonicWall released patches for both of the vulnerabilities last week. WordPress has patched one of the most critical bugs ever found in the project's code. The Vulnerability is an SQL injection in the WordPress REST API. It can be exploited by remote unauthenticated attackers to run malicious code on any WordPress site. The issue can be exploited without any preconditions and impacts all WordPress versions released since December. WordPress powers more than 41% of all Internet sites. The bug was discovered by Searchlight Cyber and is tracked as WP2 shell. And finally, a new vulnerability can crash open SSL service using an 11 bytes payload. The attack forces service to allocate huge amounts of memory before any secure TLS handshake begins and and can be exploited remotely by unauthenticated attackers. The open SSL project released patches for the bugs last month. The vulnerability was discovered by Okta and is named Holobyte. And that is all for this podcast edition. Today's show was brought to you by our sponsor, Things2Canary. Find them at Canary Tools. Thanks for your company, Sam.
Podcast: Risky Bulletin by Risky Business Media
Date: July 20, 2026
Host/Reader: Claire Aird, prepared by Catalin Cimpanu
This episode delivers a tightly-packed rundown of recent, high-impact cybersecurity events from around the world. The headline captures the catastrophic breach and wiping of Romania's land registry database, but the episode also offers concise updates on major hacks, court cases, vulnerabilities and policy programs shaping cybersecurity headlines.
Timestamp: 00:23
Timestamp: 01:15
Timestamp: 01:44
Timestamp: 02:05
Timestamp: 02:37
Timestamp: 03:09
Timestamp: 03:37
Timestamp: 03:50
Announcement:
New US program to coordinate vulnerability disclosure and patching in open source/critical infrastructure using AI tools.
Agency Involvement:
CISA, Treasury, Pentagon.
Notable Quote:
“And yeah, Gold Eagle. We’re confused about the name too.” – Claire (03:59)
Timestamp: 04:08
Timestamp: 04:45
Timestamp: 05:14
Timestamp: 05:38
Timestamp: 05:51
Timestamp: 06:08
Timestamp: 06:30
Timestamp: 06:48
Timestamp: 07:18
On Romania breach:
“The hacker gained access using valid credentials and did not try to extort the agency. The stolen data is now being offered for sale on a known hacking forum.” – Claire (00:31)
Re: Gold Eagle program's name:
“And yeah, Gold Eagle. We’re confused about the name too.” – Claire (03:59)
This episode serves as a rapid-fire yet comprehensive digest of the latest major cybersecurity stories, blending hard news on catastrophic breaches (Romania, WordPress) and threat actor activity with insights into policy changes and legal fallout for hackers. With data leaks, legal drama, and critical infrastructure at stake, the episode underscores the global, escalating, and multifaceted threats facing cyberspace in 2026.