Newsletters

Written content from the Risky Business Media team

Risky Bulletin: Hacker breaches Hungary's State Treasury

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The same hacker who hit and wiped Romania's land registry database has now hacked Hungary's State Treasury in another brazen intrusion into an extremely sensitive government system.

The incident took place last week and portions of the stolen data have since been put up for sale on an underground hacking forum.

The intrusion was confirmed to local journalists by Hungary's State Treasury over the weekend. 

Risky Bulletin: Russia is behind the recent hotel WiFi hacks

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

A Russian state-sponsored hacking group is behind a recent hacking wave that has targeted and compromised hotel WiFi gateways across the globe.

Microsoft says the campaign is far larger and more complex than it was initially covered in a ReliaQuest report two weeks ago.

ReliaQuest said the hackers were modifying DNS traffic on hotel networks to redirect users to Microsoft-themed phishing sites. Microsoft says the attacks also redirected users to malware downloads, often using ClickFix pages to trick users into downloading and running the payloads.

Risky Bulletin: Non-profit offers $22,000 bounty for INC ransomware group

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

An international crime-fighting non-profit organization is offering a $22,000 bounty for any information on members of the INC ransomware group.

To be eligible for a payout, the provided information must lead to the identification, arrest, or disruption of the gang's operations.

Crime Stoppers International is the international branch of Crime Stoppers, a US foundation that was established in the 70s to allow anonymous and private individuals to provide aid in US law enforcement investigations that may lack manpower or resources.

Srsly Risky Biz: Chipping Away at Chinese AI Risks

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

The Trump administration has been trying to address two separate AI-related risks in recent months: The specific risk to US national security from China developing powerful AI and the global risk that powerful hacking machines will be available to all and sundry. A proposed bill suggests a sensible way for the US to chip away at both these risks, at least a little.

The Collaboration on Adversarial Threats and Security Risks Act proposes safe harbor provisions for AI companies so they can share information related to AI-specific security risks. The idea here is to encourage frontier labs to work together to counter threats from Chinese AI labs, particularly what they describe as IP theft via distillation. Without this bill, sharing this kind of information could fall afoul of anti-trust legislation that prohibits collusion. 

We know the frontier labs can already detect distillation because they're always complaining about it after the fact. The idea behind this bill is that more permissive information sharing would let them respond quicker and disrupt at least some distillation campaigns.

Risky Bulletin: New Chinese cyber contractor identified

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The cyber sleuths at Intrusion Truth have uncovered a new secretive Chinese IT company that appears to work as a cyber contractor and tool developer for Chinese state-sponsored hacking operations.

Online clues appear to suggest that Guangdong Chanming appears to have developed RedRelay (aka ORBWEAVER), an ORB network (aka proxy botnet) that was used by almost a dozen Chinese APT groups to hide the origin of their attacks.

The list includes the likes of APT15, Red Vulture, Ke3chang, Vixen Panda, Playful Dragon, Nylon Typhoon, and others.

Risky Bulletin: A JSON RCE bug is about to rock the Java world

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Threat actors are exploiting a vulnerability in Alibaba's Fastjson, one of the Java ecosystem's most popular libraries for working with JSON-formatted data.

Active exploitation began last week, a day after details about the security flaw were revealed by cybersecurity firm FearsOff.

The attacks, first spotted and documented by Imperva and ThreatBook, target CVE-2026-16723, a vulnerability that can enable unauthenticated remote code execution attacks against Java projects that use the Fastjson library as a component.

Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Cybersecurity and intelligence agencies from multiple Western countries have issued joint security advisories on Thursday warning of a major Russian hacking campaign that's targeting Zimbra email servers.

The attacks have been going on since last year. The zero-day, tracked as CVE-2025-66376, was patched in November but attacks have been traced back to at least July.

The zero-day itself is a stored cross-site scripting (XSS) bug that allows the attackers to load malicious code inside a Zimbra webmail client via the CSS @import feature. The malicious code would load a web tool called Ulej (Russian for Beehive) that could be used to harvest credentials, session tokens, backup 2FA codes, browser-saved passwords, and the contents of the victim’s mailbox going back 90 days.

Srsly Risky Biz: Knives Are Out For Open-Weight AI Models

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Both the American and Chinese governments have signalled they plan to rein in open-weight AI models. 

The Trump administration seems certain to add some Chinese technology companies to the Entity List to protect investment in American frontier AI models. Meanwhile, Beijing is apparently weighing applying export restrictions on Chinese AI tech, including open-weight models.

Overnight, different US government officials issued a strong, coordinated signal that they plan to take action against Chinese AI companies. Michael Kratsios, the director of the White House's Office of Science and Technology Policy, wrote on X that Chinese company Moonshot AI had "developed a sophisticated internal platform to conduct large scale distillation against US models" and that "large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable."

Risky Bulletin: Linux kernel discloses 442 CVEs as AI bugpocalypse settles in

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The Linux kernel project has disclosed 442 vulnerabilities over the past three days, in a massive dump of CVEs on its security mailing list.

Although not confirmed, the bugs were likely discovered using AI tools. Over the past months, projects like Anthropic's Glasswing and OpenAI's Daybreak have been granting access to advanced frontier cybersecurity models to top-tier security firms and researchers to find bugs with AI in major open-source projects.

Most of the bugs are low-severity issues, so nothing world-ending for the internet today.

Risky Bulletin: Hacker wipes Romania's entire land registry database

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

A hacker has breached Romania's cadastre agency and wiped the country's entire land registry database following a failed extortion attempt.

The hack has brought Romania's entire real-estate market to a standstill as official apps and websites have been offline for a week. Notaries can't record new transactions while citizens can't obtain proof of ownership or detailed land records.

Email servers at the National Agency for Cadastre and Real Estate Advertising (Agenția Națională de Cadastru și Publicitate Imobiliară, or ANCPI) were also down as part of the incident.