{"@context":"https://schema.org","@type":"NewsArticle","generatedAt":"2026-07-23T06:40:50.084Z","headline":"黑客清空罗马尼亚全国土地登记数据库","description":"一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","url":"https://www.aioga.com/news/cmrtcc63i27b4bitlztz4gjgg/","mainEntityOfPage":"https://www.aioga.com/news/cmrtcc63i27b4bitlztz4gjgg/","datePublished":"2026-07-20T14:29:11.116Z","dateModified":"2026-07-20T14:29:11.116Z","inLanguage":"zh-CN","publisher":{"@type":"NewsMediaOrganization","name":"Aioga","url":"https://www.aioga.com"},"citation":["https://news.risky.biz/risky-bulletin-hacker-wipes-romanias-entire-land-registry-database","https://aihot.virxact.com/items/cmrtcc63i27b4bitlztz4gjgg"],"canonicalUrl":"https://www.aioga.com/news/cmrtcc63i27b4bitlztz4gjgg/","directAnswer":{"@type":"Answer","text":"Aioga 编辑摘要：一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。 Aioga 将其归入「行业动态」方向，重点关注它对真实使用和行业竞争的影响。","url":"https://www.aioga.com/news/cmrtcc63i27b4bitlztz4gjgg/","dateCreated":"2026-07-20T14:29:11.116Z","author":{"@type":"Organization","@id":"https://www.aioga.com/authors/aioga-editorial/#editorial-team","name":"Aioga Editorial Team","url":"https://www.aioga.com/authors/aioga-editorial/"}},"evidence":[{"@type":"CreativeWork","name":"news.risky.biz source article","url":"https://news.risky.biz/risky-bulletin-hacker-wipes-romanias-entire-land-registry-database","datePublished":"2026-07-20T14:29:11.116Z","provider":{"@type":"Organization","name":"news.risky.biz","url":"https://news.risky.biz/risky-bulletin-hacker-wipes-romanias-entire-land-registry-database"}},{"@type":"CreativeWork","name":"AIHot archive record","url":"https://aihot.virxact.com/items/cmrtcc63i27b4bitlztz4gjgg","datePublished":"2026-07-20T14:29:11.116Z","provider":{"@type":"Organization","name":"AIHot","url":"https://aihot.virxact.com/items/cmrtcc63i27b4bitlztz4gjgg"}}],"aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","originalPublisher":{"name":"news.risky.biz","url":"https://news.risky.biz/risky-bulletin-hacker-wipes-romanias-entire-land-registry-database"},"article":{"id":"cmrtcc63i27b4bitlztz4gjgg","slug":"cmrtcc63i27b4bitlztz4gjgg","url":"https://www.aioga.com/news/cmrtcc63i27b4bitlztz4gjgg/","title":"黑客清空罗马尼亚全国土地登记数据库","title_en":"黑客清空了罗马尼亚的土地登记数据库","summary":"一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","source":"Hacker News 热门（buzzing.cc 中文翻译）","sourceUrl":"https://news.risky.biz/risky-bulletin-hacker-wipes-romanias-entire-land-registry-database","aiHotUrl":"https://aihot.virxact.com/items/cmrtcc63i27b4bitlztz4gjgg","publishedAt":"2026-07-20T14:29:11.116Z","category":"行业动态","score":42,"selected":false,"articleBody":["In other news: Graykey maker sues former employee for leaking exploit; Hugging Face was hacked using AI; unauth RCE finally found in WordPress.","A hacker has breached Romania's cadastre agency and wiped the country's entire land registry database following a failed extortion attempt.","The hack has brought Romania's entire real-estate market to a standstill ：https://jurnaluldearges.ro/notarita-ana-stan-sunt-in-co-fortat-hackerii-au-spart-cadastrul-458711/ as official apps and websites have been offline for a week. Notaries can't record new transactions while citizens can't obtain proof of ownership or detailed land records.","Email servers at the National Agency for Cadastre and Real Estate Advertising ( Agenția Națională de Cadastru și Publicitate Imobiliară , or ANCPI) were also down as part of the incident.","Sources told Risky Business that the hacker entered using valid credentials, mapped internal systems, and wiped systems and backups after failing to extort the agency.","The incident became public on July 14 as the hacker started deleting data. A day later, some of ANCPI's stolen data was put up for sale ：https://publicrecord.ro/2026/07/17/atac-cibernetic-ancpi/ on a known hacking forum. The posted data included employee credentials, internal documents, and details on the agency's IT network.","Since the hack, officials restored their website and posted a message announcing ：https://web.archive.org/web/20260719172925/https://www.ancpi.ro/ they are rebuilding the agency's entire network from scratch. Even if the hacker claims they deleted backups, the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months in Romania.","The stolen data was posted online by an account with the name ByteToBreach , a known hacker who also breached Sweden's e-government portal ：https://darkwebinformer.com/full-source-code-of-swedens-e-government-platform-leaked-from-compromised-cgi-sverige-infrastructure/ this year, and many other government agencies and high-profile companies over the past year.","Security firm KELA published a profile on ByteToBreach last December and hinted they might be located in Algeria, but since the ANCPI hack has updated the post ：https://www.kelacyber.com/blog/bytetobreach-a-deep-dive-into-a-persistent-data-leak-operator/ and outright doxxed the hacker as Zakaria Mahdjoub , an individual from Oran, Algeria.","Well, that will make the job of Romanian law enforcement a hell lot easier! gj!","Romania joins Poland ：https://therecord.media/poland-pesel-system-state-registry-cyber-incident, Slovakia ：https://www.finsider.sk/ekonomika/kataster-nehnutelnosti-celi-kybernetickemu-utoku-nezapinajte-pocitace-vyzvali-zamestnancov/, Greece ：https://www.ktimatologio.gr/grafeio-tipou/deltia-tipou/1465, Morocco ：https://www.moroccoworldnews.com/2025/06/206486/algerian-jabaroot-group-behind-cnss-breach-attacks-moroccan-property-registry/, Russia ：https://meduza.io/en/news/2025/01/08/hackers-claim-breach-of-russia-s-real-estate-registry-leak-alleged-database-fragment, and Ukraine ：https://komersant.ua/en/khakerska-ataka-na-derzhreiestry-chy-varto-pereviriaty-maynovi-prava/ as countries that had their land registry agencies hacked over the past three years.","In this edition of Seriously Risky Business , Tom Uren and James Wilson talk about different ways ransomware groups are taking advantage of AI. The relatively new FulcrumSec group uses simple techniques to breach companies and then uses AI to get more leverage over victims in its extortion negotiations.","Hugging Face hacked using AI: A threat actor used an autonomous AI agent to breach AI platform Hugging Face last week. The attacker used exploits in the platform's data-processing pipeline to pivot to some parts of the company's internal systems. Hugging Face says no customer data was exposed but the attacker stole internal datasets and some cloud credentials. Hugging Face says it tried to use a frontier AI model to analyze the hack but was blocked by its guardrails, which couldn't differentiate between an IR event and offensive operations. [ Hugging Face ：https://huggingface.co/blog/security-incident-july-2026]","HuggingFace got hacked by an AI. What stuck out to me was the guardrail asymmetry. The attacker had no constraints, but HF's response ran afoul of the abuse guardrails, forcing them into an unplanned switch to local models. Another aspect for your IR plans. huggingface.co/blog/securit... [image or embed]：https://bsky.app/profile/did:plc:yfrzbyzye2ekirvpkzyemkxr/post/3mqujyw2ly52g?ref_src=embed","Coca-Cola hit by ransomware: Coca-Cola has suspended production at its Fairlife dairy subsidiary after a ransomware attack. In an SEC filing, Coca-Cola said hackers accessed Fairlife production-related systems this week. Production has been halted at Fairlife US factories. The company's Canadian production lines were unaffected. No ransomware group has taken credit for the incident, yet. [ SEC ：https://www.sec.gov/Archives/edgar/data/21344/000162828026048466/ko-20260716.htm // TechCrunch ：https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/]","KNPP leak: Threat intel analyst Rakesh Krishnan looks at a leak of sensitive files from India's KNPP nuclear power plant after one of its contractors got hit by the World Leaks extortion group. [ The Raven File ：https://theravenfile.com/2026/07/17/kudankulam-nuclear-power-plant-leak-an-accidental-disclosure/]","Ostium crypto-heist: The Ostium DeFi platform was hacked for $18 million last week after hackers exploited its own price-reporting infrastructure. [ CoinDesk ：https://www.coindesk.com/business/2026/07/15/ostium-suffers-usd18-million-exploit-as-oracle-attack-wave-continues-to-hit-defi]","Estée Lauder discloses Oracle EBS breach: Cosmetics giant Estée Lauder has confirmed that hackers stole customer data from its Oracle E-Business Suite platform last year. The company disclosed the breach to US state officials almost a year after it took place. This is Estée's second breach after another one in 2023. The Clop hacking group is behind the hacking spree that targeted Oracle EBS servers. [ California OAG ：https://oag.ca.gov/ecrime/databreach/reports/sb24-626688]","Ernst & Young also discloses breach: Accounting and risk management giant Ernst & Young also disclosed a breach, but the disclosure has been so sanitized of any info that I can't tell what's this about. [ California OAG ：https://oag.ca.gov/ecrime/databreach/reports/sb24-626542]","DigiCert breach linked to CylindricalCanine: Security firm Expel has linked the hack of certificate authority DigiCert to CylindricalCanine, a sub-group of GoldenEyeDog, a financially motivated group operating out of China. [ Expel ：https://expel.com/blog/introducing-cylindricalcanine/]","Ofcom opens TikTok inquiry: The UK's communications watchdog has opened a formal investigation into TikTok for failing to protect children from harmful content on the platform, as per the UK's Online Safety Act. [ Ofcom ：https://www.ofcom.org.uk/online-safety/protecting-children/investigation-into-tiktoks-compliance-with-duties-to-protect-children-from-encountering-harmful-content-under-section-12]","Moonshot releases Kimi K3: Chinese AI startup Moonshot has unveiled a new AI model named Kimi K3, which the company claims can rival the ones from top American firms like Anthropic and OpenAI. [ Kimi ：https://www.kimi.com/blog/kimi-k3 // Business Insider ：https://www.businessinsider.com/kimi-k3-ai-model-moonshot-china-open-weights-benchmarks-pricing-2026-7]","Rust in Chromium: Microsoft is working on adding a Rust-based PNG image decoder in the Chromium browser project, a more secure component for processing PNG images for Chrome, Edge, Opera, and other similar browsers. [ Microsoft ：https://microsoftedge.github.io/edgevr/posts/Rustifying-Image-Codecs-in-Chromium/]","EU password manager has ties to Russia: An investigation has revealed that Spain-based password manager Passwork shares its codebase and a \"near-identical user manual\" with a similarly-named password manager advertised in Russia. The Spanish version has allegedly been receiving software updates from an UAE firm managed by one of Passwork's Russian co-founders. The Spanish Passwork's customer list includes European government agencies and universities, which raises concerns of espionage. [ OCCRP ：https://www.occrp.org/en/investigation/european-password-manager-shares-origins-and-updates-with-state-certified-russian-firm]","India fines HP over cartel practices: The Indian government fined HP $14.4 million over cartel practices after the company colluded with resellers to fix prices for ink cartridges, toner, and other printing supplies in government contract bids. [ ArsTechnica ：https://arstechnica.com/gadgets/2026/07/hp-fined-1-4-billion-rupees-for-cartelization-of-ink-cartridges-toner-pcs/]","SanFran CAO cracks down on nudify apps: The San Francisco City Attorney's Office has sent cease-and-desist letters to Apple and Google and ordered the tech giants to remove AI nudify apps from their stores and stop indirectly profiting from CSAM. [ WIRED ：https://www.wired.com/story/san-francisco-demands-apple-and-google-delete-ai-nudify-apps-from-app-stores/]","Morocco confirmed as NSO customer: A whistleblower and former member of Morocco’s domestic intelligence service has confirmed their government's access to the NSO Pegasus spyware, contrary to the government's past public denials. The tool was heavily used to spy on dissidents, journalists, and even politicians abroad. [ OCCRP ：https://www.occrp.org/en/project/the-pegasus-project/moroccan-government-used-powerful-israeli-pegasus-spyware-to-hack-phone-of-journalist-former-intelligence-officer-says // Forbidden Stories ：https://forbiddenstories.org/codename-morgan-a-look-back-at-moroccos-acquisition-of-pegasus-involving-israel-and-the-united-arab-emirates/]","UK scraps digital ID scheme: The UK government will scrap a proposed digital ID scheme once its new prime minister Andy Burnham takes office on Monday. The scheme was announced last September and was supposed to enter into effect next year. It involved issuing a digital ID for UK citizens and legal residents in the form of a mobile app. The ID was meant to serve as proof for the Right to Work in the UK. [ Reuters ：https://www.reuters.com/world/uk/next-uk-prime-minister-andy-burnham-drops-digital-id-scheme-2026-07-18/]","US govt fails to rotate cyber personnel: The US government failed to follow through with one of its own programs to rotate cybersecurity employees between federal agencies. Only eight employees participated in the program since 2022. The program was meant to teach employees new skills before returning to their native agencies. [ GAO ：https://www.gao.gov/products/gao-26-108736 // Cyberscoop ：https://cyberscoop.com/opm-federal-rotational-cyber-workforce-program-gao/]","White House announces Gold Eagle program: The Trump administration has launched a new program to help coordinate the disclosure and patching of vulnerabilities in open-source projects and critical infrastructure. The new Gold Eagle program was designed to receive bug reports at scale, usually found using AI tools and frontier AI models. CISA, the Treasury Department, and the Pentagon are involved in the program. [ White House ：https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/]","France bans Polymarket: The French government has ordered internet service providers to block access to prediction market betting platform Polymarket. The French regulatory authority formally banned the platform in 2024 and threatened fines of up to €200,000 for French citizens placing bets on the platform. The agency moved into active enforcement after data showed Polymarket's userbase grew in France despite the ban. Spain also banned Polymarket in May. [ Engadget ：https://www.engadget.com/2218130/france-doubles-down-on-restricting-access-to-polymarket/]","In this Risky Business sponsor interview , Casey Ellis chats with Haroon Meer from Thinkst about building companies customers don’t hate. Haroon explains why Thinkst still offers Canary tokens for free and why it has avoided annual price hikes on its paid products. They talk about Eric Ries’s “Incorruptible”, Rob Lee’s 100-year-company approach at Dragos, and why keeping customers happy is a better business strategy than chasing easy sugar highs.","Graykey maker sues employee for leaking exploit: Graykey-maker Magnet Forensics has sued a former employee for allegedly leaking details about a proprietary iPhone exploit. Magnet claims Mario Del Gaudio shared details of the exploit with his new employer and rival company Paradigm Shift. The exploit was tracked internally at Magnet as MSG but was disclosed publicly by Paradigm Shift in a blog post as usbliter8. The exploit allows attackers to run malicious code inside the SecureROM of Apple devices using A12 and A13 chips. It is a hardware bug and unpatchable. [ Bloomberg ：https://www.bloomberg.com/news/articles/2026-07-17/iphone-hacking-firm-sues-ex-worker-over-alleged-theft-of-secrets // CourtListener ：https://www.courtlistener.com/docket/73584326/magnet-forensics-llc-v-del-gaudio/ // usbliter8 blog post ：https://ps.tc/pages/blog-usbliter8.html]","TfL hackers get five years: A UK judge has sentenced two members of the Scattered Spider hacking group to 5.5 years in prison each. Thalha Jubair and Owen Flowers pleaded guilty last month to hacking the London public transport authority in August of 2024. The hack caused months of disruptions at Transport for London and caused damages of £39 million. Jubair is also charged in the US with hacking and extorting 47 US companies and allegedly seeking ransoms of at least $115 million. [ NCA ：https://www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever-cyber-crime-case]","REvil hacker arrested in Armenia: Armenian authorities have arrested a suspected member of the REvil ransomware group. Alexander Ermakov was arrested at the Yerevan airport at the end of June on an Interpol arrest warrant. A man named Alexander Ermakov is the main suspect behind the ransomware attack on Australia's Medibank insurer in 2022. Russian media claims that Armenian authorities arrested a man with the same name and that the real Ermakov is in Russia, where he is serving a restriction of freedom sentence that prevents him from traveling abroad. [ RIA Novosti ：https://ria.ru/20260716/armenija-2105285622.html // Risky Business ：https://risky.biz/au-uk-us-sanction-russian-behind-medibank-hack/]","Scam center dismantled in Timor-Leste: Police in Timor-Leste have raided three cyber scam compounds in the capital city of Dili. Police arrested 253 suspects, with most being Chinese and Indonesian nationals. Authorities also raided another compound last month. [ ABC ：https://www.abc.net.au/news/2026-07-15/timor-scam-compound-chinese-indonesians-cambodians-arrested/106913210]","DHS seizes 30,000 mobile SIM cards: The DHS Homeland Security Investigations seized more than 30,000 mobile SIM cards in June and July as part of a crackdown against telephone fraud. [ Bloomberg ：https://www.bloomberg.com/news/articles/2026-07-16/dhs-seizes-30-000-mobile-sim-cards-in-effort-to-stop-phone-fraud]","GTA hacker released from hospital, sent to prison: A member of the Lapsus$ hacking group has been released from a secure hospital and transferred to a normal prison in the UK. Arion Kurtaj is set to face trial again for hacking Rockstar Games in 2022 and releasing GTA5 source code and GTA6 gameplay. Kurtaj was diagnosed with severe autism and sentenced to an indefinite hospital order in December 2023. [ GameRant ：https://gamerant.com/gta-6-hacker-trial-november/ // Polygon ：https://www.polygon.com/gta-6-leak-hacker-what-happened-trial-burner-phone-selfies-hospital/]","UAT-11795 profile: Cisco is tracking a new e-crime group targeting companies in the US and Europe with the Starland RAT and a command-and-control (C2) memory implant named the WLDR Agent. [ Cisco Talos ：https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/]","TAG-150 evolution: eSentire has published details on the changes to the tradecraft of TAG-150, an e-crime group behind the CastleLoader, CastleBot, and CastleRAT malware strains—also tracked as DinDoor, a Deno-based loader, NightshadeC2, and DenoRAT, a Deno-based Remote Access Trojan (RAT). The biggest change is their adoption of ClickFix, everyone's favorite infection vector. [ eSentire ：https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft]","More ViPNeT exploitation in Russia: A hacking group is planting backdoors inside Russian companies using the ViPNet enterprise VPN software. The attackers first compromise one VPN node and then exploit the software's update mechanism to install the backdoor on the whole network. ViPNet owner Infotecs has confirmed the attacks and released security updates. A similar wave of attacks also took place in April last year. [ Infotecs ：https://infotecs.ru/press-center/publications/razyasneniya-kompanii-infotecs-po-intsidentu-svyazannomu-s-rasprostraneniem-vredonosnogo-po/ // PositiveTechnologies ：https://habr.com/ru/companies/pt/articles/1060016/ // Kaspersky ：https://securelist.com/tr/hellonet-vipnet/120700/ // Last year's attacks ：https://securelist.ru/new-backdoor-mimics-security-software-update/112326/]","Scarcity scams are here to stay: Scarcity scams are a new category of online scams where threat actors run fake sites for online services with limited availability or spots. This type of scam has exploded across the past few years and typically target the reservation sites of various government websites across the world. [ DomainTools ：https://dti.domaintools.com/securitysnacks/scarcity-scams]","Sextortion campaigns: A recent spike in sextortion email scams has been linked to the good ol' Trik/Phorpiex botnet, which is still alive after all these years. [ PointWild ：https://www.pointwild.com/threat-intelligence/phorpiex-inside-the-botnet-powering-global-sextortion-spam-operations/]","Text salting in the wild: Threat actors are using a technique named \"text salting\" to hide text inside their emails and bypass email spam filters for both traditional and AI-powered email security systems. Barracuda has seen the technique used in over a million retail-themed phishing scams. [ Barracuda ：https://blog.barracuda.com/2026/07/16/text-salting-ai-email-security]","RubyGems malware: At least two dormant RubyGems accounts have been compromised to push malware to old projects. [ Aikido Security ：https://www.aikido.dev/blog/sleepergem-rubygems-supply-chain-attack // Step Security ：https://www.stepsecurity.io/blog/sleepergem-compromised-rubygems-drop-persistent-backdoor]","OAuth Client ID Spoofing: Threat actors are using OAuth client ID spoofing to abuse Microsoft Entra ID for account enumeration, check password validity, and account state. The technique is seeing increased usage, per Proofpoint. [ Proofpoint ：https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy]","Proofpoint observed two independent campaigns adopting this tradecraft: • UNK_PyReq2323: >1M targeted users, 700K+ spoofed client IDs • UNK_OutFlareAZ: >2M targeted users, 3.7M spoofed client IDs Different tooling and infrastructure suggest growing adoption.","XZ Utils backdoor: Adrian Mastronardi has published a book with the in-depth story of the XZ Utils backdoor incident from 2024. [ Half a Second ：https://www.half-second.com/]","Pegasus spyware: The security team at Amnesty International has published the most comprehensive analysis of the Pegasus spyware to date, leveraging the insights from past reports and the recent WhatsApp lawsuit. [ Amnesty International ：https://securitylab.amnesty.org/latest/2026/07/inside-pegasus-the-evolution-of-the-worlds-most-notorious-spyware/]","ClickLock Stealer: A new infostealer targeting macOS users has been spotted in the wild. This one has been named ClickLock because it blends ClickFix and locker tactics for its distribution and installation process. [ Group-IB ：https://www.group-ib.com/blog/clicklock-stealer-macos-malware/]","CrashStealer: There's also another macOS infostealer in the wild, named CrashStealer because it tries to impersonate Apple's crash-reporting framework to harvest browser credentials, cryptocurrency wallets, and keychain data. [ Jamf ：https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/]","ACR Stealer: Microsoft has reported an increase in attacks deploying the ACR Stealer across customer environments since April. [ Microsoft ：https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/]","BoryptGrab: Almost 300 GitHub repositories impersonating legitimate software were actually spreading a version of the BoryptGrab infostealer. [ Arctic Wolf ：https://arcticwolf.com/resources/blog/fake-github-repositories-deliver-boryptgrab-lineage-infostealer/]","TELEPUZ: Elastic has spotted a new malware framework being deployed in the wild that appears to be related to an upcoming MaaS. [ Elastic ：https://www.elastic.co/security-labs/telepuz-maas-malware-clickfix]","Spirals ransomware: Broadcom's Symantec team has spotted a new ransomware strain named Spirals being deployed in Asia. Not much information about it so far. [ Broadcom ：https://www.security.com/threat-intelligence/ransomware-spirals-extortion]","NadMesh botnet: A newly discovered botnet is specifically targeting AI infrastructure and the MCP ecosystem. The NadMesh botnet has targeted Ollama, ComfyUI, and other AI-related servers since early July. The botnet plants SSH backdoors for control and future access. According to Chinese security firm QiAnXin, the botnet appears to be an \"industrial-grade\" operation with a \"clear commercial intent.\" [ QiAnXin ：https://blog.xlab.qianxin.com/nadmesh-botnet-analysis-a-product-grade-threat-for-the-ai-service-era-en/]","OkoBot framework: Researchers have found a new modular malware framework named OkoBot that resembles an infostealer but puts more focus on stealing sensitive data from cryptocurrency owners and related services. [ Kaspersky ：https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660/]","WackoGinx phishing kit: Researchers have found a new phishing kit named WackoGinx (also WachoGinx) that can run campaigns targeting M365, Facebook, Gmail, LinkedIn, and PayPal. [ Threatactix ：https://threatactix.com/2026/07/02/a-rare-look-inside-the-command-and-control-panel-behind-modern-phishing-operations/]","In this Soap Box edition of the podcast, Patrick Gray chats with Thinkst Canary founder Haroon Meer about his \"decade of deception.\"","UTA0533 is behind new SonicWall zero-day wave: A hacking group tracked as UTA0533 is behind two zero-days exploited in SonicWall SMA appliances. The zero-days include an SSRF and a code injection vulnerability that grant the group root-level access to the device. The attacks began in late June and are deploying malware designed specifically for SonicWall SMA VPN appliances. SonicWall released patches for both zero-days last week. [ Volexity ：https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/ // SonicWall patches ：https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008]"],"articleImages":[{"sourceUrl":"https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/size/w160/2024/01/BXRruXC9_400x400.png","alt":"Catalin Cimpanu","afterParagraph":0,"url":"/media/articles/cmrtcc63i27b4bitlztz4gjgg/4204b130724df728.png"},{"sourceUrl":"https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/Rowenna.png","alt":"","afterParagraph":25,"url":"/media/articles/cmrtcc63i27b4bitlztz4gjgg/725212061346fffa.png"},{"sourceUrl":"https://storage.ghost.io/c/16/e9/16e9a748-ca66-4b3c-8590-85537131f696/content/images/2026/07/wacko.png","alt":"","afterParagraph":57,"url":"/media/articles/cmrtcc63i27b4bitlztz4gjgg/c45e2b87eab6fff5.png"}],"mediaStatus":"ok","articleBodyZh":["在其他新闻中：Graykey 制造商起诉前员工泄露漏洞；Hugging Face 被使用 AI 攻击；WordPress 中终于发现未经授权的 RCE 漏洞。","一名黑客入侵了罗马尼亚的地籍机构，并在勒索未遂后清空了该国的整个土地登记数据库。","此次黑客事件导致罗马尼亚整个房地产市场陷入停滞：https://jurnaluldearges.ro/notarita-ana-stan-sunt-in-co-fortat-hackerii-au-spart-cadastrul-458711/，官方应用程序和网站已离线一周。公证人无法记录新的交易，市民无法获取所有权证明或详细的土地记录。","国家地籍与房地产广告局（Agenția Națională de Cadastru și Publicitate Imobiliară，简称 ANCPI）的邮件服务器也因该事件而停止运行。","消息人士告诉 Risky Business，黑客使用有效凭证进入系统，绘制了内部系统图，并在勒索未果后清除了系统和备份。","该事件于 7 月 14 日曝光，当时黑客开始删除数据。一天后，一些 ANCPI 被盗数据被放到已知黑客论坛上出售：https://publicrecord.ro/2026/07/17/atac-cibernetic-ancpi/。发布的数据包括员工凭证、内部文档以及机构 IT 网络的详细信息。","自黑客事件发生以来，官方已恢复网站，并发布消息宣布：https://web.archive.org/web/20260719172925/https://www.ancpi.ro/ 他们正在从零开始重建整个机构网络。即使黑客声称删除了备份，机构似乎仍有离线副本，否则未来几个月罗马尼亚的情况可能会非常混乱。","被盗数据由名为 ByteToBreach 的账户在网上发布，该黑客今年还入侵了瑞典的电子政务门户：https://darkwebinformer.com/full-source-code-of-swedens-e-government-platform-leaked-from-compromised-cgi-sverige-infrastructure/，在过去一年中还入侵了许多其他政府机构和知名公司。","安全公司 KELA 去年十二月发布了有关 ByteToBreach 的资料，并暗示他们可能位于阿尔及利亚，但自从 ANCPI 黑客事件后，该帖子已更新：https://www.kelacyber.com/blog/bytetobreach-a-deep-dive-into-a-persistent-data-leak-operator/ 并直接曝光了黑客 Zakaria Mahdjoub，他是阿尔及利亚奥兰的一名个人。","好了，这将大大简化罗马尼亚执法部门的工作！干得好！","罗马尼亚加入了波兰：https://therecord.media/poland-pesel-system-state-registry-cyber-incident、斯洛伐克：https://www.finsider.sk/ekonomika/kataster-nehnutelnosti-celi-kybernetickemu-utoku-nezapinajte-pocitace-vyzvali-zamestnancov/、希腊：https://www.ktimatologio.gr/grafeio-tipou/deltia-tipou/1465、摩洛哥：https://www.moroccoworldnews.com/2025/06/206486/algerian-jabaroot-group-behind-cnss-breach-attacks-moroccan-property-registry/、俄罗斯：https://meduza.io/en/news/2025/01/08/hackers-claim-breach-of-russia-s-real-estate-registry-leak-alleged-database-fragment 和乌克兰：https://komersant.ua/en/khakerska-ataka-na-derzhreiestry-chy-varto-pereviriaty-maynovi-prava/ 成为过去三年中其土地登记机构遭受黑客攻击的国家。","在本期《严重风险业务》中，Tom Uren 和 James Wilson 讨论了勒索软件组织利用人工智能的不同方式。相对新成立的 FulcrumSec 组使用简单的技术入侵公司，然后利用人工智能在勒索谈判中对受害者获得更大的影响力。","Hugging Face 利用 AI 被黑：上周，一名威胁行为者使用自主 AI 代理攻击了 AI 平台 Hugging Face。攻击者利用平台数据处理管道中的漏洞入侵公司内部系统的部分区域。Hugging Face 表示没有客户数据泄露，但攻击者窃取了内部数据集和一些云凭证。Hugging Face 表示尝试使用前沿 AI 模型分析黑客事件，但被其防护措施阻挡，防护措施无法区分事故响应事件和攻击操作。[ Hugging Face：https://huggingface.co/blog/security-incident-july-2026 ]","HuggingFace 被 AI 攻击。让我印象深刻的是防护不对称性。攻击者没有任何限制，但 HF 的响应却触碰了滥用防护规则，迫使他们不得不临时切换到本地模型。这是你 IR 计划中的另一个方面。huggingface.co/blog/securit... [图片或嵌入]：https://bsky.app/profile/did:plc:yfrzbyzye2ekirvpkzyemkxr/post/3mqujyw2ly52g?ref_src=embed","可口可乐遭遇勒索软件攻击：可口可乐在其 Fairlife 乳制品子公司遭遇勒索软件攻击后暂停生产。在美国证券交易委员会的备案中，可口可乐表示黑客本周访问了 Fairlife 与生产相关的系统。Fairlife 美国工厂的生产已被停止。该公司在加拿大的生产线未受影响。目前尚未有勒索软件组织声称对此事件负责。[ SEC：https://www.sec.gov/Archives/edgar/data/21344/000162828026048466/ko-20260716.htm // TechCrunch：https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/]","KNPP 泄露：威胁情报分析师 Rakesh Krishnan 研究了印度 KNPP 核电站的敏感文件泄露事件，该事件发生在其一名承包商遭到 World Leaks 勒索组织攻击后。[ The Raven File：https://theravenfile.com/2026/07/17/kudankulam-nuclear-power-plant-leak-an-accidental-disclosure/]","Ostium 加密货币抢劫事件：Ostium DeFi 平台上周被黑客攻击，损失 1800 万美元，原因是黑客利用了其价格报告基础设施。[ CoinDesk：https://www.coindesk.com/business/2026/07/15/ostium-suffers-usd18-million-exploit-as-oracle-attack-wave-continues-to-hit-defi]","雅诗兰黛披露 Oracle EBS 漏洞：化妆品巨头雅诗兰黛证实，去年黑客从其 Oracle E-Business Suite 平台窃取了客户数据。公司在事件发生近一年后才向美国州政府官员披露此漏洞。这是雅诗兰黛在 2023 年之后的第二次数据泄露。Clop 黑客组织是此次针对 Oracle EBS 服务器攻击浪潮的幕后黑手。[ California OAG：https://oag.ca.gov/ecrime/databreach/reports/sb24-626688]","安永也披露了数据泄露：会计和风险管理巨头安永也披露了一次数据泄露，但披露的信息被高度净化，以至于我无法判断具体情况。[加州总检察长办公室：https://oag.ca.gov/ecrime/databreach/reports/sb24-626542]","DigiCert泄露与CylindricalCanine有关：安全公司Expel将证书颁发机构DigiCert的黑客事件与CylindricalCanine联系起来，后者是GoldenEyeDog的一个子组织，这个组织是一个从中国运作的以经济利益为动机的团体。[Expel：https://expel.com/blog/introducing-cylindricalcanine/]","Ofcom对TikTok展开调查：据英国《在线安全法》，英国通讯监管机构Ofcom已对TikTok未能保护儿童免受平台有害内容影响展开正式调查。[Ofcom：https://www.ofcom.org.uk/online-safety/protecting-children/investigation-into-tiktoks-compliance-with-duties-to-protect-children-from-encountering-harmful-content-under-section-12]","Moonshot发布Kimi K3：中国AI初创公司Moonshot推出了一款名为Kimi K3的新AI模型，公司称其可以与美国顶级公司如Anthropic和OpenAI的模型竞争。[Kimi：https://www.kimi.com/blog/kimi-k3 // 商业内幕：https://www.businessinsider.com/kimi-k3-ai-model-moonshot-china-open-weights-benchmarks-pricing-2026-7]","Chromium中的Rust：微软正在Chromium浏览器项目中添加基于Rust的PNG图像解码器，这是一个用于处理Chrome、Edge、Opera及其他类似浏览器PNG图像的更安全的组件。[微软：https://microsoftedge.github.io/edgevr/posts/Rustifying-Image-Codecs-in-Chromium/]","欧盟密码管理器与俄罗斯有关：调查显示，总部位于西班牙的密码管理器Passwork与俄罗斯广告的同名密码管理器共享代码库和“几乎相同的用户手册”。据称，西班牙版本的软件更新由由Passwork一位俄罗斯联合创始人管理的阿联酋公司提供。西班牙Passwork的客户名单包括欧洲政府机构和大学，引发了间谍活动的担忧。[OCCRP：https://www.occrp.org/en/investigation/european-password-manager-shares-origins-and-updates-with-state-certified-russian-firm]","印度因卡特尔行为罚款惠普：印度政府因惠普公司与经销商串通，在政府合同投标中操纵墨盒、碳粉和其他打印耗材的价格，向惠普处以1440万美元罚款。 [ArsTechnica：https://arstechnica.com/gadgets/2026/07/hp-fined-1-4-billion-rupees-for-cartelization-of-ink-cartridges-toner-pcs/]","旧金山市律师办公室打击“去衣”应用：旧金山市律师办公室向苹果和谷歌发送了停止侵权函，并下令科技巨头从其应用商店中删除AI去衣应用，并停止间接从儿童性虐待材料（CSAM）中获利。 [WIRED：https://www.wired.com/story/san-francisco-demands-apple-and-google-delete-ai-nudify-apps-from-app-stores/]","摩洛哥被确认使用NSO：一名举报人及摩洛哥国内情报机构前成员确认其政府使用NSO Pegasus间谍软件，这与政府此前的公开否认相矛盾。该工具被大量用于监控持不同政见者、记者，甚至海外政治人物。 [OCCRP：https://www.occrp.org/en/project/the-pegasus-project/moroccan-government-used-powerful-israeli-pegasus-spyware-to-hack-phone-of-journalist-former-intelligence-officer-says // Forbidden Stories：https://forbiddenstories.org/codename-morgan-a-look-back-at-moroccos-acquisition-of-pegasus-involving-israel-and-the-united-arab-emirates/]","英国取消数字身份证计划：英国政府将在新首相安迪·伯纳姆周一上任后取消拟议中的数字身份证计划。该计划于去年九月宣布，原定于明年生效。该计划涉及向英国公民和合法居民发行以移动应用形式呈现的数字身份证，用作在英国工作的权利证明。 [Reuters：https://www.reuters.com/world/uk/next-uk-prime-minister-andy-burnham-drops-digital-id-scheme-2026-07-18/]","美国政府未能轮换网络安全人员：美国政府未能贯彻其自身的一项计划，将网络安全员工在联邦机构之间轮换。自2022年以来，仅有八名员工参与了该计划。该计划的目的是在员工返回原机构之前教授新技能。 [GAO：https://www.gao.gov/products/gao-26-108736 // Cyberscoop：https://cyberscoop.com/opm-federal-rotational-cyber-workforce-program-gao/]","白宫宣布“金鹰”计划：特朗普政府启动了一项新计划，以帮助协调开源项目和关键基础设施中漏洞的披露与修补。新的“金鹰”计划旨在大规模接收漏洞报告，这些漏洞通常通过AI工具和前沿AI模型发现。CISA、财政部和五角大楼参与了该计划。 [白宫：https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/]","法国禁止Polymarket：法国政府已要求互联网服务提供商阻止访问预测市场博彩平台Polymarket。法国监管机构在2024年正式禁止该平台，并威胁对在该平台下注的法国公民处以最高20万欧元罚款。在数据显示尽管被禁止，Polymarket在法国的用户仍在增长后，该机构开始积极执法。西班牙也在5月禁止了Polymarket。 [Engadget：https://www.engadget.com/2218130/france-doubles-down-on-restricting-access-to-polymarket/]","在这期《Risky Business》赞助商访谈中，Casey Ellis与Thinkst的Haroon Meer聊了如何建立客户不讨厌的公司。Haroon解释了为什么Thinkst仍然免费提供Canary令牌，以及为什么其付费产品避免了年度涨价。他们讨论了Eric Ries的《不可腐蚀》（Incorruptible）、Rob Lee在Dragos的百年公司理念，以及为什么保持客户满意比追逐短期利益是更好的商业策略。","Graykey 制造商起诉员工泄露漏洞：Graykey 制造商 Magnet Forensics 起诉了一名前员工，称其泄露了一种专有 iPhone 漏洞的详细信息。Magnet 声称 Mario Del Gaudio 将该漏洞的详细信息分享给了他的现任雇主及竞争公司 Paradigm Shift。该漏洞在 Magnet 内部被标记为 MSG，但由 Paradigm Shift 在博客文章中公开披露，命名为 usbliter8。该漏洞允许攻击者在配备 A12 和 A13 芯片的苹果设备的 SecureROM 内部运行恶意代码。这是一个硬件漏洞，无法修补。 [Bloomberg：https://www.bloomberg.com/news/articles/2026-07-17/iphone-hacking-firm-sues-ex-worker-over-alleged-theft-of-secrets // CourtListener：https://www.courtlistener.com/docket/73584326/magnet-forensics-llc-v-del-gaudio/ // usbliter8 博客文章：https://ps.tc/pages/blog-usbliter8.html]","TfL 黑客被判五年：英国一名法官判处 Scattered Spider 黑客组织的两名成员各监禁 5.5 年。Thalha Jubair 和 Owen Flowers 上个月承认有罪，他们于 2024 年 8 月入侵伦敦公共交通管理局。这次入侵导致伦敦交通局数月中断，并造成 3900 万英镑的损失。Jubair 还在美国面临指控，称他入侵并敲诈了 47 家美国公司，并涉嫌寻求至少 1.15 亿美元的赎金。[NCA：https://www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever-cyber-crime-case]","REvil 黑客在亚美尼亚被捕：亚美尼亚当局逮捕了一名疑似 REvil 勒索软件组织成员。Alexander Ermakov 于六月底在埃里温机场被捕，这是根据国际刑警组织的逮捕令进行的。名为 Alexander Ermakov 的男子是 2022 年对澳大利亚 Medibank 保险公司进行勒索软件攻击的主要嫌疑人。俄罗斯媒体称，亚美尼亚当局逮捕了一名同名男子，而真正的 Ermakov 目前在俄罗斯服刑，受到限制自由的判决，禁止出国旅行。[RIA Novosti：https://ria.ru/20260716/armenija-2105285622.html // Risky Business：https://risky.biz/au-uk-us-sanction-russian-behind-medibank-hack/]","东帝汶拆除诈骗中心：东帝汶警方突袭了首都帝力的三个网络诈骗据点。警方逮捕了253名嫌疑人，其中大多数是中国和印尼国籍。有关部门上个月还突袭了另一个据点。[ABC：https://www.abc.net.au/news/2026-07-15/timor-scam-compound-chinese-indonesians-cambodians-arrested/106913210]","国土安全部查获30,000张手机SIM卡：国土安全部的国土安全调查局在6月和7月查获了超过30,000张手机SIM卡，这是针对电话诈骗的打击行动的一部分。[Bloomberg：https://www.bloomberg.com/news/articles/2026-07-16/dhs-seizes-30-000-mobile-sim-cards-in-effort-to-stop-phone-fraud]","GTA黑客出院被送入监狱：Lapsus$黑客组织的一名成员已从安全医院出院并被转移到英国的普通监狱。Arion Kurtaj将再次因2022年入侵Rockstar Games并泄露GTA5源码及GTA6游戏内容而接受审判。Kurtaj被诊断为严重自闭症，并于2023年12月被判无限期医院令。[GameRant：https://gamerant.com/gta-6-hacker-trial-november/ // Polygon：https://www.polygon.com/gta-6-leak-hacker-what-happened-trial-burner-phone-selfies-hospital/]","UAT-11795概况：Cisco正在跟踪一个新的电子犯罪团伙，此团伙使用Starland RAT及名为WLDR Agent的指挥与控制（C2）内存植入程序，针对美国和欧洲的公司发起攻击。[Cisco Talos：https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/]","TAG-150演变：eSentire发布了关于TAG-150电子犯罪团伙技术工艺变化的详细信息，该团伙是CastleLoader、CastleBot和CastleRAT恶意软件的幕后组织——也被追踪为DinDoor（基于Deno的加载器）、NightshadeC2以及DenoRAT（一种基于Deno的远程访问木马）。最大的变化是他们采用了ClickFix，这是大家喜爱的感染载体。[eSentire：https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft]","俄罗斯ViPNeT被利用事件增加：一个黑客组织正在使用ViPNet企业VPN软件在俄罗斯公司内部植入后门。攻击者首先入侵一个VPN节点，然后利用该软件的更新机制在整个网络中安装后门。ViPNet所有者Infotecs已确认这些攻击并发布了安全更新。去年四月也发生过类似的攻击浪潮。[ Infotecs：https://infotecs.ru/press-center/publications/razyasneniya-kompanii-infotecs-po-intsidentu-svyazannomu-s-rasprostraneniem-vredonosnogo-po/ // PositiveTechnologies：https://habr.com/ru/companies/pt/articles/1060016/ // Kaspersky：https://securelist.com/tr/hellonet-vipnet/120700/ // 去年的攻击：https://securelist.ru/new-backdoor-mimics-security-software-update/112326/]","稀缺性骗局将持续存在：稀缺性骗局是一种新型的网络骗局，威胁行为者会运营声称服务有限或名额有限的假网站。这类骗局在过去几年中迅速蔓延，通常针对世界各地政府网站的预约系统。[ DomainTools：https://dti.domaintools.com/securitysnacks/scarcity-scams]","勒索色情活动：近期勒索色情电子邮件骗局激增，这与仍然活跃的Trik/Phorpiex僵尸网络有关，尽管经过多年仍在运行。[ PointWild：https://www.pointwild.com/threat-intelligence/phorpiex-inside-the-botnet-powering-global-sextortion-spam-operations/]","文本盐化技术在野外使用：威胁行为者正在使用一种名为“文本盐化”的技术，将文本隐藏在电子邮件中，以绕过传统和AI驱动的邮件安全系统的垃圾邮件过滤。Barracuda已在超过一百万次以零售为主题的网络钓鱼骗局中发现了此技术的使用。[ Barracuda：https://blog.barracuda.com/2026/07/16/text-salting-ai-email-security]","RubyGems恶意软件：至少有两个休眠的RubyGems账户被入侵，用于向旧项目推送恶意软件。[ Aikido Security：https://www.aikido.dev/blog/sleepergem-rubygems-supply-chain-attack // Step Security：https://www.stepsecurity.io/blog/sleepergem-compromised-rubygems-drop-persistent-backdoor]","OAuth 客户端 ID 欺骗：威胁行为者正在使用 OAuth 客户端 ID 欺骗来滥用 Microsoft Entra ID，以进行账户枚举、检查密码有效性和账户状态。据 Proofpoint 称，该技术的使用频率正在上升。[ Proofpoint：https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy]","Proofpoint 观察到两个独立的活动采用了这一技术：• UNK_PyReq2323：>100 万被攻击用户，超过 70 万个伪造客户端 ID • UNK_OutFlareAZ：>200 万被攻击用户，370 万个伪造客户端 ID 不同的工具和基础设施表明采用量在增长。","XZ Utils 后门：Adrian Mastronardi 出版了一本书，深入讲述了 2024 年 XZ Utils 后门事件的故事。[ Half a Second：https://www.half-second.com/]","Pegasus 间谍软件：国际特赦组织的安全团队发布了迄今为止最全面的 Pegasus 间谍软件分析，利用了过去报告的见解以及近期 WhatsApp 诉讼的资料。[ Amnesty International：https://securitylab.amnesty.org/latest/2026/07/inside-pegasus-the-evolution-of-the-worlds-most-notorious-spyware/]","ClickLock 信息窃取程序：一款针对 macOS 用户的新型信息窃取程序已在野外被发现。由于其将 ClickFix 和 locker 技术融合用于分发和安装流程，因此被命名为 ClickLock。[ Group-IB：https://www.group-ib.com/blog/clicklock-stealer-macos-malware/]","CrashStealer：另一款 macOS 信息窃取程序也在野外出现，名为 CrashStealer，因为它试图冒充 Apple 的崩溃报告框架以收集浏览器凭据、加密货币钱包和钥匙串数据。[ Jamf：https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/]","ACR Stealer：微软报告称，自四月以来，针对客户环境部署 ACR Stealer 的攻击有所增加。[ Microsoft：https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/]","BoryptGrab：近 300 个冒充正规软件的 GitHub 存储库实际上散布了 BoryptGrab 信息窃取程序的一个版本。[ Arctic Wolf：https://arcticwolf.com/resources/blog/fake-github-repositories-deliver-boryptgrab-lineage-infostealer/]","TELEPUZ：Elastic 发现了一种正在野外部署的新型恶意软件框架，似乎与即将推出的 MaaS 有关。[Elastic：https://www.elastic.co/security-labs/telepuz-maas-malware-clickfix]","Spirals 勒索软件：Broadcom 的 Symantec 团队在亚洲发现了一种名为 Spirals 的新型勒索软件。目前关于它的信息不多。[Broadcom：https://www.security.com/threat-intelligence/ransomware-spirals-extortion]","NadMesh 僵尸网络：新发现的僵尸网络专门针对 AI 基础设施和 MCP 生态系统。自七月初以来，NadMesh 僵尸网络已针对 Ollama、ComfyUI 及其他 AI 相关服务器。该僵尸网络植入 SSH 后门以实现控制和未来访问。根据中国安全公司奇安信的说法，该僵尸网络似乎是一次“工业级”行动，并具有“明确的商业意图”。[奇安信：https://blog.xlab.qianxin.com/nadmesh-botnet-analysis-a-product-grade-threat-for-the-ai-service-era-en/]","OkoBot 框架：研究人员发现了一种名为 OkoBot 的新型模块化恶意软件框架，它类似信息窃取工具，但更多地侧重于窃取加密货币所有者及相关服务的敏感数据。[卡巴斯基：https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660/]","WackoGinx 网络钓鱼工具包：研究人员发现了一种名为 WackoGinx（也称 WachoGinx）的新型网络钓鱼工具包，可以运行针对 M365、Facebook、Gmail、LinkedIn 和 PayPal 的活动。[Threatactix：https://threatactix.com/2026/07/02/a-rare-look-inside-the-command-and-control-panel-behind-modern-phishing-operations/]","在本期 Soap Box 播客中，Patrick Gray 与 Thinkst Canary 创始人 Haroon Meer 聊了聊他的“十年欺骗经历”。","UTA0533 是新一波 SonicWall 零日漏洞攻击的幕后黑手：一个被追踪为 UTA0533 的黑客组织是 SonicWall SMA 设备中被利用的两个零日漏洞的幕后黑手。这些零日漏洞包括 SSRF 和代码注入漏洞，使该组织能够获得设备的根级访问权限。攻击始于六月下旬，并部署专门针对 SonicWall SMA VPN 设备的恶意软件。SonicWall 上周发布了针对这两个零日漏洞的补丁。[ Volexity：https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/ // SonicWall 补丁：https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008]"],"translationStatus":"translated","bodyOrigin":"source-page","editorial":{"summary":"Aioga 编辑摘要：一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。 Aioga 将其归入「行业动态」方向，重点关注它对真实使用和行业竞争的影响。","background":"背景分析：公司与行业类动态需要放在竞争格局、商业化路径、资本信号和监管环境中观察，单条公告不能代表最终结果。","viewpoint":"Aioga 判断：这条动态更适合作为行业观察信号，当前信息足以建立线索，但不足以推导长期结论。","implications":"影响分析：对相关团队而言，短期应先核对来源、可用范围和实际成本，再判断是否值得接入或跟进。","nextStep":"后续观察：继续观察官方文件、合作落地、收入或用户信号、竞品动作和监管后续。","evidenceRefs":["title","summary","articleBody"],"confidence":"medium","status":"published","aiGenerated":false,"autoApproved":true,"generatedBy":"rule-safe-fallback","generatedAt":"2026-07-23T06:49:19.103Z","sourceHash":"7826c56a3cc0d03c","validation":{"passed":true,"mode":"rule-safe-fallback","checks":["schema","length","source-attribution","no-html"]}},"tags":["行业动态","Hacker News 热门（buzzing.cc 中文翻译）"],"translations":{"zh-CN":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"行业动态","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Aioga AI资讯","description":"一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","url":"https://www.aioga.com/news/cmrtcc63i27b4bitlztz4gjgg/"},"en":{"title":"黑客清空了罗马尼亚的土地登记数据库","summary":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under Industry. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"Industry","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空了罗马尼亚的土地登记数据库 - Aioga AI News","description":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under Industry. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息...","url":"https://www.aioga.com/en/news/cmrtcc63i27b4bitlztz4gjgg/"},"ja":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aiogaは「業界動向」の動きとして、Hacker News 热门（buzzing.cc 中文翻译） からの更新を追跡しています。一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"業界動向","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Aioga AIニュース","description":"Aiogaは「業界動向」の動きとして、Hacker News 热门（buzzing.cc 中文翻译） からの更新を追跡しています。一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCP...","url":"https://www.aioga.com/ja/news/cmrtcc63i27b4bitlztz4gjgg/"},"ko":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aioga는 Hacker News 热门（buzzing.cc 中文翻译）의 업데이트를 업계 동향 흐름으로 추적합니다. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"업계 동향","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Aioga AI 뉴스","description":"Aioga는 Hacker News 热门（buzzing.cc 中文翻译）의 업데이트를 업계 동향 흐름으로 추적합니다. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI...","url":"https://www.aioga.com/ko/news/cmrtcc63i27b4bitlztz4gjgg/"},"es":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aioga sigue esta actualización de Hacker News 热门（buzzing.cc 中文翻译） dentro de Industria. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"Industria","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Aioga Noticias de IA","description":"Aioga sigue esta actualización de Hacker News 热门（buzzing.cc 中文翻译） dentro de Industria. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、...","url":"https://www.aioga.com/es/news/cmrtcc63i27b4bitlztz4gjgg/"},"fr":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aioga suit cette mise à jour de Hacker News 热门（buzzing.cc 中文翻译） dans la catégorie Industrie. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"Industrie","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Aioga Actualités IA","description":"Aioga suit cette mise à jour de Hacker News 热门（buzzing.cc 中文翻译） dans la catégorie Industrie. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还...","url":"https://www.aioga.com/fr/news/cmrtcc63i27b4bitlztz4gjgg/"},"de":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"行业动态","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Aioga KI-News","description":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论...","url":"https://www.aioga.com/de/news/cmrtcc63i27b4bitlztz4gjgg/"},"pt-BR":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"行业动态","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Aioga Notícias de IA","description":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论...","url":"https://www.aioga.com/pt-BR/news/cmrtcc63i27b4bitlztz4gjgg/"},"ru":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"行业动态","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Aioga Новости ИИ","description":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论...","url":"https://www.aioga.com/ru/news/cmrtcc63i27b4bitlztz4gjgg/"},"ar":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"行业动态","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Aioga أخبار الذكاء الاصطناعي","description":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论...","url":"https://www.aioga.com/ar/news/cmrtcc63i27b4bitlztz4gjgg/"},"hi":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"行业动态","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Aioga AI समाचार","description":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论...","url":"https://www.aioga.com/hi/news/cmrtcc63i27b4bitlztz4gjgg/"},"it":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"行业动态","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Aioga Notizie IA","description":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论...","url":"https://www.aioga.com/it/news/cmrtcc63i27b4bitlztz4gjgg/"},"nl":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"行业动态","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Aioga AI-nieuws","description":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论...","url":"https://www.aioga.com/nl/news/cmrtcc63i27b4bitlztz4gjgg/"},"tr":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"行业动态","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Aioga AI Haberleri","description":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论...","url":"https://www.aioga.com/tr/news/cmrtcc63i27b4bitlztz4gjgg/"},"vi":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"行业动态","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Tin tức AI Aioga","description":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论...","url":"https://www.aioga.com/vi/news/cmrtcc63i27b4bitlztz4gjgg/"},"id":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"行业动态","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Berita AI Aioga","description":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论...","url":"https://www.aioga.com/id/news/cmrtcc63i27b4bitlztz4gjgg/"},"th":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"行业动态","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - ข่าว AI Aioga","description":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论...","url":"https://www.aioga.com/th/news/cmrtcc63i27b4bitlztz4gjgg/"},"pl":{"title":"黑客清空罗马尼亚全国土地登记数据库","summary":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论坛上出售。ANCPI 已宣布从零重建整个网络，但据信拥有离线备份。","category":"行业动态","source":"news.risky.biz","aggregationSource":"Hacker News 热门（buzzing.cc 中文翻译）","pageTitle":"黑客清空罗马尼亚全国土地登记数据库 - Aioga Wiadomości AI","description":"Aioga tracks this update from Hacker News 热门（buzzing.cc 中文翻译） under 行业动态. 一名黑客入侵罗马尼亚国家土地登记局（ANCPI），在勒索失败后清空了全国土地登记数据库，导致官方应用和网站瘫痪一周，不动产市场陷入停滞。黑客使用有效凭证进入系统，删除数据后还将员工凭证、内部文档等被盗信息在黑客论...","url":"https://www.aioga.com/pl/news/cmrtcc63i27b4bitlztz4gjgg/"}}}}