HyperAIHyperAI

Command Palette

Search for a command to run...

a day ago
Security

Hacker Wipes Romania’s Land Registry After Failed Extortion

Romania’s national land registry has been paralyzed after a sophisticated cyberattack wiped the country’s entire cadastre database and compromised internal backups. The breach, publicly disclosed on July 14, was orchestrated by a threat actor operating under the alias ByteToBreach, later identified as Zakaria Mahdjoub from Oran, Algeria. According to security sources, the intruder gained initial access using valid credentials, mapped the National Agency for Cadastre and Real Estate Advertising infrastructure, and executed a destructive data purge following a failed extortion demand. The attack has halted real estate transactions nationwide, disabling official portals, email systems, and notarial processing capabilities for over a week. While officials have taken the agency website offline to rebuild the network from scratch, technical indicators suggest an offline backup may exist, potentially mitigating long-term recovery delays. Stolen credentials and network architecture details were subsequently listed for sale on underground forums. This incident underscores a broader acceleration in ransomware and data-destructive campaigns targeting critical government and commercial infrastructure. In parallel, the AI sector faced a significant breach when threat actors deployed an autonomous AI agent to exploit a data-processing pipeline vulnerability at the Hugging Face platform, pivoting to internal systems and exfiltrating datasets alongside cloud credentials. The attack revealed operational friction, as internal security guardrails inadvertently blocked AI-assisted incident response tools. Corporate operations were similarly disrupted when Coca-Cola suspended production at its Fairlife dairy subsidiary following a ransomware intrusion that compromised manufacturing systems, while Qantas disclosed that a 5.7 million-customer data breach originated from a targeted social engineering campaign against an overseas contractor. Threat intelligence reports highlight a rapid shift in attacker tradecraft, notably the widespread adoption of ClickFix, a social engineering payload delivery method now utilized by advanced persistent threat groups including Sandworm. The malware landscape has also seen the emergence of specialized macOS infostealers leveraging locker tactics and impersonation frameworks to harvest cryptocurrency assets and browser credentials. Concurrently, researchers have published comprehensive analyses of the 2024 XZ Utils supply chain compromise, examining its impact on global software dependencies. On the vulnerability and policy front, the WordPress foundation released an urgent patch for a critical unauthenticated SQL injection flaw in the REST API that affects a significant portion of global websites. Security teams are also monitoring a memory allocation exploit targeting OpenSSL servers that bypasses TLS handshakes. Regulatory developments include the UK government decision to abandon its proposed digital ID scheme, France enforcement actions against a prediction betting platform, and the US administration launch of a new initiative to streamline vulnerability disclosure and patching for critical open-source infrastructure. As state-sponsored and financially motivated actors continue to refine supply chain, AI-assisted, and social engineering vectors, organizations are prioritizing network reconstruction, credential rotation, and hardened incident response protocols to maintain operational continuity.

Related Links