Sponsored by

|
Fact
|
The HexStrike AI framework broke into thousands of internet-facing Citrix NetScaler systems in under 10 minutes using a single CVE, while CISA still gives federal defenders a standard 15-day window to patch known-exploited flaws. (Booz Allen Hamilton report, March 2026)
|
|
|
Nothing says "digital transformation" like a country losing the ability to buy a house because one guy didn't get his ransom paid. Threat model accordingly. This week isn't really about hackers getting smarter, it's about how much of real life, property records, bank logins, your company's AI assistant, now depends on infrastructure nobody budgeted to protect. Here's what changed, what got worse, and one habit that actually helps.
PS — Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe →
|
|
In this edition
|
|
|
|
|
| |
🏛️ Privacy, Power & Policy |
|
|
|
|
|
|
Critical Infrastructure
🏚️ A Cyberattack Froze an Entire Country's Property Market for a Week
Intro
Romania's national land registry went dark for nearly a week this month, and with it, the ability to buy or sell property anywhere in the country. All because one guy allegedly didn't get paid.
What Happened
A threat actor going by ByteToBreach broke into ANCPI, Romania's land registry agency, using leaked credentials, then took down its systems and stole source code for its e-Terra platform after the agency refused to pay. Real estate transactions nationwide froze starting July 14: notaries couldn't verify deeds, banks couldn't confirm mortgages.
Why It Matters
Threat intel firm Kela says ByteToBreach isn't a nation-state operation, just a financially motivated broker allegedly run by one Algeria-based individual, Zakaria Mahdjoub. One person with leaked credentials froze an entire country's real estate market.
The Other Side
Officials note the attack was "not very complex," and that core cadastral and legal ownership records were never compromised. This was an availability failure, not a data integrity one.
| |
👉 Takeaway
Critical government infrastructure keeps failing to basic access hygiene, not nation-state tradecraft. ANCPI had reportedly been warned about these gaps and spent a fraction of its budget on security anyway.
|
TL;DR: One broker with leaked logins knocked an entire country's property market offline for a week.
|
| |
Data Breach
Craneware, a UK billing software maker whose systems touch thousands of US hospitals and pharmacies, confirmed hackers stole a "significant volume" of customer data, including employee and partner records. Its 2021 acquisition of pharmacy software Sentry came with access to 147 million patient records built up over two decades, though Craneware hasn't disclosed how much of that was touched this time. No group has claimed credit, and the company hasn't said whether attackers demanded a ransom.
→ The healthcare supply chain keeps getting hit through vendors nobody outside IT has heard of, not the hospitals themselves.
|
| |
Ransomware
The Clop ransomware gang is exploiting CVE-2026-12569, a critical unauthenticated remote-code-execution flaw in PTC's Windchill and FlexPLM software, used by over 30,000 customers across aerospace, defense, automotive, and medtech. Clop's playbook is familiar: deploy webshells to steal data, then blast extortion emails to hundreds of employees at each victim, exactly what it did with MOVEit and Oracle EBS, a campaign that hit over 2,770 organizations. Unpaid, the stolen files land on Clop's leak site, available via torrent.
→ If your company touches Windchill or FlexPLM, assume Clop already has a list with your name on it.
|
| |
Malware
A malvertising operation dubbed SourTrade impersonates TradingView, Solana, and Luno to target crypto investors and retail traders across 12 countries in 25 languages. Instead of delivering finished malware, it fingerprints visitors, then assembles a working Windows executable piece by piece inside the browser using a legitimate Bun runtime and AES-CTR-encrypted chunks, so no complete malicious file ever touches the network. It's delivered via a hidden iframe with spoofed file-download headers. Researchers at Confiant say that construction makes hash-based detection essentially useless.
→ If your antivirus is still hunting for known malware signatures, campaigns like this one walk right past it.
|
|
The AI Agent You Can Trust
The best assistants don't multitask their attention across a hundred tools. Neither does Catch. It's an AI agent that focuses on one thing — the admin work you'd rather not touch — and does it exceptionally well.
Scheduling, flights, restaurants, follow-ups, vendors, clients. You hand it over; Catch handles the back-and-forth and comes back with it done.
No context-switching. No dropped balls. Just your admin, quietly cleared — so your focus stays on the work only you can do.
| |
AI Security
Security firm Zenity Labs found a flaw in ChatGPT's Agent Builder, nicknamed AgentForger, that let a single tampered link hijack agent creation and stand up an attacker-controlled agent using a real employee's permissions, approvals switched off. The bug abused two parameters in the Builder's initialization URL to inject instructions directly into the build process. The forged agent inherited whatever the employee had authorized, email, calendar, cloud storage, Slack, Teams, and could exfiltrate data and impersonate the employee indefinitely. OpenAI fixed the flaw in June; researchers published the technical details this week.
→ Every enterprise AI agent inherits its owner's blast radius. One click shouldn't hand that radius to an attacker.
|
| |
AI Security
Researchers found a sandbox escape in Anthropic's Claude Cowork, nicknamed SharedRoot, that let an AI agent break out of its Linux VM and reach the host Mac's filesystem, including SSH keys, cloud credentials, and browser data. The escape chained a filesystem mount meant to be root-only in the guest VM with CVE-2026-46331, a high-severity Linux kernel privilege-escalation bug. Roughly 500,000 Mac users running local Cowork sessions were exposed before Anthropic closed the report as informative rather than shipping a direct fix. The issue is effectively neutralized now that the latest Cowork version defaults new sessions to cloud execution instead of a local VM.
→ A sandbox is only as strong as the one door nobody thought to lock.
|
|
|
🏛️ Privacy, Power & Policy
|
|
| |
Policy
The Trump administration unveiled Gold Eagle, a federal clearinghouse run out of Treasury that uses AI, including Anthropic's Mythos model, to identify and prioritize software vulnerabilities across government and critical infrastructure. Treasury, the Pentagon, DHS, CISA, and open-source maintainers are all plugged in, aiming to coordinate patches before attackers find the same flaws. National Cyber Director Sean Cairncross says it enables "vulnerability and patching coordination at a speed and scale never seen before." It runs under the CISA 2015 Act's information-sharing authority, which expires in September and needs Congress to renew it.
→ A government AI vulnerability system is only as useful as Congress's willingness to keep funding it past this fall.
|
| |
Privacy
California's DROP tool lets residents submit one request that reaches all 614 registered data brokers, covering social security numbers, geolocation, browsing history, and even inferred data like health predictions. It launched January 1, with compliance mandatory for registered brokers by August 1, and users get a trackable DROP ID for each request. The catch: it only reaches brokers who actually registered, so anyone skipping that step, or non-brokers like Google, stays untouched. Public record data like vehicle or real estate ownership isn't covered either.
→ It's the most usable data-deletion tool a state has shipped yet. Use it, but don't mistake it for full coverage.
|
|
| |
Practical play
Eclypsium's new InfraTrust report, first in a planned monthly series, flagged 61 infrastructure advisories from 14 vendors this month, including SonicWall SMA1000, Fortinet FortiSandbox, Dell Networking OS10/SmartFabric Manager, F5 BIG-IP, and Juniper/NVIDIA data-center gear. Six of those advisories are critical and 26 are remotely exploitable without authentication. Its pitch: rank patches by exploitability, reachability, and real-world exposure, not raw CVSS score, since firmware updates for edge and networking gear routinely lag the upstream fix.
→ Triaging patches this week? Start with whatever's internet-facing and unauthenticated, that's where InfraTrust says the real risk sits.
|
|
Introducing The First Agentic CRM
Get revenue agents, workflows, and automations across every stage of your motion. Access customer data in real time through Attio's web app, MCP, API, and SDK.
Then Ask Attio anything about your business and get instant answers.
It's the CRM that runs the work behind every win.
Strange but real
🏦 North Korea Arrested Its Own Hackers for Robbing Its Own Banks
Intro
North Korea's elite state hackers spend their careers stealing from everyone else. This month, some of them got arrested for stealing from North Korea.
What Happened
According to South Korea-based outlet Daily NK, North Korean authorities arrested former military intelligence cyber operators on July 12 for hacking the Central Bank of the DPRK and the Foreign Trade Bank, the institutions that oversee the country's currency and foreign payments. The group allegedly siphoned funds in small increments, laundering proceeds into dollars and yuan through Chinese brokers, before investigators traced encrypted traffic to a safe house in Pyongyang.
Why It Matters
North Korea's state hacking apparatus is blamed for roughly $577 million in stolen crypto this year alone, about 76% of all tracked global crypto hack losses. Apparently that pipeline has an internal leak.
The Other Side
Reporting comes from Daily NK via South Korean media and hasn't been independently verified. Treat the details as credible but not confirmed.
| |
👉 Takeaway
Even a regime built entirely around offensive hacking can't fully secure its own financial infrastructure from its own operators.
|
TL;DR: North Korea's own hackers allegedly robbed North Korea's own banks, and got arrested for it.
|
You already follow the model launches, benchmarks, and breakthroughs. Now trade on what happens next. Explore real-world AI and tech markets on Kalshi. Trade $25, get up to $500.