Risky Bulletin: Hacker breaches Hungary's State Treasury
In other news: Russia to mandate 40 apps on all smartphones next year; hackers hits Liechtenstein's business database; AI hallucinates 55 vulnerability reports.
This newsletter is brought to you by Permiso Security. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.
The same hacker who hit and wiped Romania's land registry database has now hacked Hungary's State Treasury in another brazen intrusion into an extremely sensitive government system.
The incident took place last week and portions of the stolen data have since been put up for sale on an underground hacking forum.
The intrusion was confirmed to local journalists by Hungary's State Treasury over the weekend.
Treasury officials claim it only impacted its Agricultural and Rural Development Office (MVH) and that unlike Romania's case, no data was lost or wiped in the attack.
But just like in Romania's case, the Hungary incident was later revealed to have been a data exfiltration attack followed by a data encryption attack with a highly-volatile and brittle ransomware strain.
The encrypted Treasury systems have since been isolated while the country's cybersecurity agency is investigating.
According to Telex, the alleged entry point was an unpatched Oracle WebLogic server. The same publication says that based on the screenshots shared by the hacker, the incident is a 10/10 in terms of severity and the access the attacker had.
The hacker, known as ByteToBreach, initially played coy and claimed he had no idea where the data came from or its importance, but later admitted that he carried out the intrusion for his personal profit.
This is consistent with the hacker's past activity, which goes back almost a year and seems to be focused on making money from anywhere he can, more than making political statements.
After the hack in Romania, security firm KELA doxxed the hacker as Zakaria Mahdjoub, an individual from Oran, Algeria, information that may now come in handy to a second country.
A hacker has breached Hungary's State Treasury and stolen sensitive government data.
The incident took place last week.
The State Treasury claims it only impacted its Agricultural and Rural Development Office.
The hack was carried out by a hacker named ByteToBreach, the same individual who hacked and wiped Romania's land registry database last month.
Hungarian officials said there was no data loss in their case.
Risky Business Podcasts
In this edition of Between Two Nerds, Tom Uren and The Grugq talk about whether hacker culture is inherently anti-authoritarian and how different states get their country's hackers to work for the state.
Breaches, hacks, and security incidents
UKGI data breach: The UK state investment body has exposed sensitive information online for two days due to a staffer's error. The personal information of 51 government officials was exposed during the past financial year. The UKGI says the staffer failed to follow security protocols. [UKGI // The Telegraph]
Cyberattack hits Liechtenstein's business database: Hackers have stolen sensitive data from Liechtenstein's business register. The database contains sensitive information on the owners of Liechtenstein companies. There are more than 31,000 businesses registered in the small European country. [Euronews]
Switzerland's BIT agency was hacked: Hackers have breached more than 200 accounts at the Swiss national IT agency BIT. The intrusion originated at the agency's Microsoft SharePoint servers. BIT says it found no evidence of data exfiltration. The agency manages more than 50,000 workstations for government workers and more than 1,000 government apps. [Swiss government]
Allstate investigates breach: American insurer Allstate is investigating a security breach after its name has been listed on the dark web leak site of a new and very prodigious group going by the name of ExfilSquad. [AzatTV]
Intermarché breach: French supermarket Intermarché said hackers stole the data of nearly 300,000 customers. The breach took place last week. The company operates supermarkets in France, Belgium, Portugal, and Belgium. [Le Figaro]
Żabka breach: And since we're on supermarket chains, one in Poland also got popped. Żabka says the hackers entered via the account of a third-party service provider. [Żabka]
Iran water hacks spread to 12 states: At least a dozen US states are responding to cyberattacks against local water systems. The number has risen from seven to 12 over the course of two days. Some of the new public incidents have been reported in Clayton County, Georgia and the city of Duchesne, Utah. Customers were left low pressure or no water in Clayton County in the middle of the night last week. In Utah, the cyberattack made pumps run dry while their control panels said they were pumping water. The incident impacted an oilfield wastewater disposal site but did not cause any environmental damage. Iranian hackers are behind the intrusions. [ABC News // DysruptionHub // DysruptionHub]
Coinkite destroys inventory after hack: Crypto-wallet maker Coinkite has destroyed all its stock of Coldcard hardware wallets following the discovery of a major bug. Hackers exploited the vulnerability to steal close to $130 million in user funds since last week. The company has released a patch for the older Coldcard wallets but does not intend to sell them anymore. The vulnerability is still being actively exploited against users who failed to install the firmware update. [Coinkite]
BeaconCRM hack impacts UK charities: Hackers have breached BeaconCRM, a popular customer management platform used by UK charities. The intruders allegedly stole data on donors and their donations. Numerous UK charities started notifying donors this week. Some of the affected organizations include the English National Ballet, the Center for Sustainable Energy, and the Gardens Trust. Beacon claims to serve more than 1,000 charities. [BBC // Arts Professional // CSE // The Chiswick Calendar] [h/t @maxsec.bsky.social]
AI, general tech, and privacy
Samsung bans TV proxy apps: Samsung will ban smart TV apps that share a user's bandwidth with third-party services. Samsung becomes the second smart TV maker to ban apps with proxy functionality from their app stores. Research published in June found that more than a third of all LG and Samsung smart TVs were running an app that was secretly sharing their internet connection with a proxy service. [TechCrunch // Mnemonic // Spur]
Apple sues employees, OpenAI: Apple has sued and requested an injunction against two former employees who now work for OpenAI. The tech giant claims that the ex-staff are in possession of confidential information and trade secrets that they plan to use at their next workplace at OpenAI. The frontier lab denied the claims. [Reuters // OpenAI]
Apple challenges the UK again: Apple has launched a new legal challenge against the UK's attempt to get the company to grant it access to iCloud user backups for law enforcement investigations. [The Record]
In hindsight, I think the term exceptional access is better than lawful access. A backdoor could hypothetically be lawful access. But we're still not talking about a backdoor here. A backdoor is a covert mechanism intended to allow the bypassing of a normal authentication system. That ain't this.
— Alexander Martin (@alexmartin.bsky.social) August 4, 2026 at 1:07 PM
[image or embed]
Myspace wants a return: Former mega-social media network MySpace is planning a return as a no-algorithm alternative to the current social media hellscape. [The Source]
KPN to refund "security filter" tax: Dutch ISP KPN will have to refund users the €1 tax it added to their monthly subscriptions as an optional malware scanner and security filter that's not even turned on—if users requested it. [Consumentenbond]
New PQC issue: Ivan Ristic at Red Sift looks at a problem with implementing PQC protections, namely that post-quantum signatures are about 34 times larger than regular crypto signatures and are creating performance bottlenecks in TCP connection windows. [Red Sift]
Microsoft reduces NuGet API key lifetime: Microsoft is reducing the lifetime of new NuGet API keys from 365 to 30 days. The new change will enter into effect starting August 17, in two weeks. On November 1, Microsoft also intends to invalidate any NuGet API keys created before August 17. The shorter lifespan is meant to reduce the sprawl of any supply chain attacks. [Microsoft]
Government, politics, and policy
White House finalizes AI framework: The White House says it finalized a framework for evaluating AI models, meeting an August 1 deadline set by the Trump administration earlier this year. The White House invited the big AI frontier labs to read and test the framework on Tuesday. Officials don't plan to release the framework publicly. [Axios // CNBC // Axios]
US prepares Chinese data center equipment ban: The US Federal Communications Commission is working on an import ban on Chinese-made data center equipment. The order will primarily target optical transceivers, used to transfer data inside data centers. Officials are using the argument of national security. The US has already banned the import of Chinese-made routers, drones, robots, and solar inverters. [Reuters]
ICE's new surveillance dragnet: The US ICE has built a giant internet surveillance dragnet that scours the web for negative comments about the agency and tries to track down and prosecute authors. [WSJ]
US RECOVER PII Act: US lawmakers have introduced a bill—the Reducing the Effects of the Cyberattack on OPM Victims Enduring Response and Protecting Identifiable Information Act, or RECOVER PII Act—to provide identity protection to the victims of the OPM 2015 breach forever. The coverage for the hack is set to expire in September. [Sen. Warner // CyberScoop]
Chinese telcos never left the US: Three Chinese telcos have maintained presence on the US market despite an FCC ban. China Mobile, China Telecom, and China Unicom maintained network connections, equipment, and data center space. US lawmakers fear the leftover equipment and connections could be used to hack and spy on US targets. [NextGov]
Russia to mandate 40 pre-installed apps: The Russian government will require that all smartphones sold in the country come pre-installed with 40 apps. The list of apps includes the state messenger MAX, the Russian government's Mir payment app, the Kaspersky antivirus, Russia's Play Store alternative Rustore, and several Yandex and VK apps. The order enters into effect next year. [Prava // Kommersant]
Russia bans 20 new VPNs: Russia's internet watchdog has banned 20 more VPN services this week, bringing the country's total close to 500 apps and services. Some of the banned VPN providers reported losing access to their IP address blocks. The government is also preparing a whitelist of VPN services allowed to be used for business and corporate services. [PT's SecurityLab]
Russia to extend SORM to crypto and gaming: The Russian government plans to extend the SORM internet surveillance system to cryptocurrency exchanges and gaming platforms. Companies will have to provide data on their users to the FSB intelligence service in real time. The Russian government greatly expanded the type of data collected via SORM equipment earlier this year. [The Bell // Risky Bulletin]
Websites of Russian banks break: The websites of at least seven major Russian banks were showing errors on Monday after certificate authorities revoked their TLS certificates. Errors were reported on the sites of VTB, Sberbank, Alfa-Bank, Rosselkhozbank, Promsvyazbank, Uralsib, and the St. Petersburg Bank. The portals switched to certificates issued by the Russian government, which are not trusted by foreign-made browsers. [Fontanka]

Sponsor section
In this Risky Business sponsor interview, James Wilson chats with Permiso CTO Ian Ahl about detecting ShinyHunters-style attackers as they move through cloud and SaaS environments.
Arrests, cybercrime, and threat intel
OpenAI disrupts Cambodian scam center: OpenAI has banned ChatGPT accounts used by a Cambodian scam center for romance, investment, and law enforcement impersonation scams. The ChatGPT accounts were also used to craft fake job ads aimed to recruit Indian nationals and lure them to Cambodia. OpenAI says the scam compound operated near the city of Poipet, near Cambodia's border with Thailand. [OpenAI]
SMS blaster detained in Hong Kong: Chinese authorities have arrested a 31-year-old for driving with an SMS blaster across Hong Kong. The suspect allegedly sent out waves of SMS messages to phish WhatsApp users for their device pairing code. Once inside an account, the hackers would demand money from the victim's friends and family. [CommsRisk]
Malware moves to D2IP connections: Almost half of today's malware samples connect to their command and control servers directly via IP address. The new technique allows malware to bypass DNS-based security systems, since no domain resolution ever takes place. According to Palo Alto Networks, this includes ransomware droppers, peer-to-peer botnets, and malware used in supply chain attacks. [Palo Alto Networks]
SMOKE#SCREEN campaign: Securonix looks at one of the many social engineering campaigns targeting workers at large corps, seeking to collect their credentials and infect their workstations with RMM malware. [Securonix]
FBI issues swatting alert: The FBI warns there's an increase in swatting and fake bomb calls across the US. The Bureau published a few tips on how to spot these. [FBI IC3]
Malicious VS Code extensions: Researchers have found 77 malicious VS Code extensions uploaded on the OpenVSX marketplace. The extensions mimicked legitimate tools in what is called an evil twin attack. [Manifold Security]
AI prevalent in African cybercrime: More than half of cybercrime police cases across Africa involved the use of AI in some capacity. According to Interpol, AI is now used in all stages of a cyber attack, from reconnaissance to malware development. The agency says AI usage has seen a "dramatic increase" from previous years and represents a "fundamental shift in criminal methodology." [Interpol]
Malicious links in AI summaries: Security researchers have found malicious links in 1.7% of AI summaries for the world's largest banks and retail brands. This included links to phishing pages and malware downloads. The test included summaries from four AI services, such as ChatGPT, Copilot, Gemini, and Perplexity. Perplexity returned the highest number of malicious links while Copilot the fewest. [Netcraft]

Malware technical reports
ChainDrop npm worm: A new worm is spreading across the npm ecosystem. The initial spread point has been traced back to the keyv and cacheable npm packages, both managed by the same developer. The new worm has already spread to more than 440 other npm libraries. It's named ChainDrop, runs in the Bun runtime, harvests cloud and CI credentials, and then spreads to other packages. [Aikido Security // DataDog // OpenSourceMalware // SafeDep // Semgrep // Socket Security // Step Security // Wiz]
Greatness PhaaS: ZeroBEC looks at Greatness, a Phishing-as-a-Service platform advertised on Telegram for a whopping $289/month. [ZeroBEC]
New Java Stealer: A threat actor is distributing a new Java-based infostealer to Roblox users looking for cheats on underground forums and Discord channels. [Bitdefender]
DOUBLECUP LaaS: There's now a new malware loader-as-a-service (LaaS) sold to cybercrime groups that was specifically designed for use in ClickFix campaigns. [SOCRadar]
Lotus wiper: Malware researcher 0x0d4y has reverse-engineered Lotus Wiper, the data wiper used in the attack against Venezuela's state oil company PDVSA last December, before the US abducted the country's president. [0x0d4y]
Interlock ransomware: The Interlock ransomware group is abusing a well-known incident response tool in recent attacks. The group has used the Volatility software to dump a computer's memory and search for any credentials. According to Sophos, Interlock has been abusing Volatility since May, mainly for lateral movement. [Sophos]
CRPX0 ransomware: Threat intel analyst Rakesh Krishnan looks at CRPX0, a new ransomware portal that launched last month and which is allegedly being run by a well-known crypto scammer. This is an interesting report because you usually see this migration the other way around, from ransomware to crypto scams. [The Raven File]

Sponsor section
Learn how Permiso Security discovers, protects, and defends all of your human, non-human and AI identities in this short intro.
APTs, cyber-espionage, and info-ops
Twill Typhoon's QuickFox supply chain attack: Hackers have compromised the QuickFox VPN app to deploy a backdoor on its users' systems. The malware has been active in the official QuickFox app since August last year. The app is primarily used by Chinese international students and expats to access gaming servers and websites inside China. Fortinet says open-source evidence suggests the Twill Typhoon APT group might be behind the attack. [Fortinet]

Vulnerabilities, security research, and bug bounty
Security updates: cPanel, N-able.
N-able zero-day: Software maker N-able has released security fixes for an actively-exploited zero-day (CVE-2026-18577) targeting its N-central remote management product. All N-central versions ever released are impacted. Attacks were spotted last Friday and the company has now released a second set of patches to address the issue—after the first one didn't work. [N-able status page // N-able patch]
Vulnerability allowed DNA evidence tampering: Academics from the University of New Haven have found a bug that can allow undetectable modifications to HID files, used to store DNA data. The files are generated by software used in crime-lab equipment. Thermo Fisher Scientific, the software's maker, has released a security update to patch the issue. [WSJ]
Pass-ta-key attack: Researchers at Palo Alto Networks have developed three techniques to bypass passkey authentication and hijack a user's account. The attack requires malware on a user's system and abuses the password manager feature in Google Chrome. A variation of the attack also allows the malware to steal the browser's password manager master key. This can be used to decrypt and steal future passkeys and private keys and impersonate users. [Palo Alto Networks]
AI hallucinates vulnerability reports: An AI vulnerability scanner has obtained CVE identifiers for 55 hallucinated bug reports. In most cases, the cited vulnerable code didn't exist, mentioned unrelated functions, or the POCs didn't work. One of the hallucinated bugs was an SQLite vulnerability with a severity of 10/10. All the CVE identifiers have since been withdrawn. [JFrog // SQLite // All the LLM slop reports]
Microsoft gives out $20m to bug hunters: Microsoft has awarded $20 million to security researchers for bugs reported through its official bug bounty program. The funds went to 562 researchers across 15 bounty programs. The largest award was $200,000. The total also includes the $2.3 million given to winners at the Zero Day Quest hacking contest.

Infosec industry
Threat/trend reports: BlackFog, CrowdStrike, Databarracks, Dataminr, DCSO, Interpol, NASCIO-Deloitte, and Resilience have recently published reports and summaries covering various emerging threats and industry trends.

Acquisition news: VISA will acquire Israeli startup BioCatch, which provides AI-based fraud detection. [Quartz]
Into the Breach: OPSWAT and MythBusters' Kari Byron will be launching a cybersecurity focused docu-series this week called Into the Breach. [OPSWAT]
New tool—Cyber Incident Registry: DysruptionHub has launched the Cyber Incident Registry, a database of cyber disruptions by incident, affected organization, location, ransomware group, and critical infrastructure sector.
BSides LV 2026 streams: Live streams from the BSides Las Vegas 2026 security conference, which is taking place this week, are available on YouTube.
Risky Business podcasts
In this edition of Seriously Risky Business, Tom Uren and James Wilson talk about open-weight AI models and distillation. These topics have been subject to a lot of US government attention in recent weeks, but let's not forget that America's overriding goal is to remain ahead of China in the AI race.