在本期《严重风险业务》中,Tom Uren 和 James Wilson 讨论了勒索软件组织利用人工智能的不同方式。相对新成立的 FulcrumSec 组使用简单的技术入侵公司,然后利用人工智能在勒索谈判中对受害者获得更大的影响力。
Hugging Face 利用 AI 被黑:上周,一名威胁行为者使用自主 AI 代理攻击了 AI 平台 Hugging Face。攻击者利用平台数据处理管道中的漏洞入侵公司内部系统的部分区域。Hugging Face 表示没有客户数据泄露,但攻击者窃取了内部数据集和一些云凭证。Hugging Face 表示尝试使用前沿 AI 模型分析黑客事件,但被其防护措施阻挡,防护措施无法区分事故响应事件和攻击操作。[ Hugging Face:https://huggingface.co/blog/security-incident-july-2026 ]
HuggingFace 被 AI 攻击。让我印象深刻的是防护不对称性。攻击者没有任何限制,但 HF 的响应却触碰了滥用防护规则,迫使他们不得不临时切换到本地模型。这是你 IR 计划中的另一个方面。huggingface.co/blog/securit... [图片或嵌入]:https://bsky.app/profile/did:plc:yfrzbyzye2ekirvpkzyemkxr/post/3mqujyw2ly52g?ref_src=embed
OAuth 客户端 ID 欺骗:威胁行为者正在使用 OAuth 客户端 ID 欺骗来滥用 Microsoft Entra ID,以进行账户枚举、检查密码有效性和账户状态。据 Proofpoint 称,该技术的使用频率正在上升。[ Proofpoint:https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy]
Proofpoint 观察到两个独立的活动采用了这一技术:• UNK_PyReq2323:>100 万被攻击用户,超过 70 万个伪造客户端 ID • UNK_OutFlareAZ:>200 万被攻击用户,370 万个伪造客户端 ID 不同的工具和基础设施表明采用量在增长。
UTA0533 是新一波 SonicWall 零日漏洞攻击的幕后黑手:一个被追踪为 UTA0533 的黑客组织是 SonicWall SMA 设备中被利用的两个零日漏洞的幕后黑手。这些零日漏洞包括 SSRF 和代码注入漏洞,使该组织能够获得设备的根级访问权限。攻击始于六月下旬,并部署专门针对 SonicWall SMA VPN 设备的恶意软件。SonicWall 上周发布了针对这两个零日漏洞的补丁。[ Volexity:https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/ // SonicWall 补丁:https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008]
In other news: Graykey maker sues former employee for leaking exploit; Hugging Face was hacked using AI; unauth RCE finally found in WordPress.
A hacker has breached Romania's cadastre agency and wiped the country's entire land registry database following a failed extortion attempt.
The hack has brought Romania's entire real-estate market to a standstill :https://jurnaluldearges.ro/notarita-ana-stan-sunt-in-co-fortat-hackerii-au-spart-cadastrul-458711/ as official apps and websites have been offline for a week. Notaries can't record new transactions while citizens can't obtain proof of ownership or detailed land records.
Email servers at the National Agency for Cadastre and Real Estate Advertising ( Agenția Națională de Cadastru și Publicitate Imobiliară , or ANCPI) were also down as part of the incident.
Sources told Risky Business that the hacker entered using valid credentials, mapped internal systems, and wiped systems and backups after failing to extort the agency.
The incident became public on July 14 as the hacker started deleting data. A day later, some of ANCPI's stolen data was put up for sale :https://publicrecord.ro/2026/07/17/atac-cibernetic-ancpi/ on a known hacking forum. The posted data included employee credentials, internal documents, and details on the agency's IT network.
Since the hack, officials restored their website and posted a message announcing :https://web.archive.org/web/20260719172925/https://www.ancpi.ro/ they are rebuilding the agency's entire network from scratch. Even if the hacker claims they deleted backups, the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months in Romania.
The stolen data was posted online by an account with the name ByteToBreach , a known hacker who also breached Sweden's e-government portal :https://darkwebinformer.com/full-source-code-of-swedens-e-government-platform-leaked-from-compromised-cgi-sverige-infrastructure/ this year, and many other government agencies and high-profile companies over the past year.
Security firm KELA published a profile on ByteToBreach last December and hinted they might be located in Algeria, but since the ANCPI hack has updated the post :https://www.kelacyber.com/blog/bytetobreach-a-deep-dive-into-a-persistent-data-leak-operator/ and outright doxxed the hacker as Zakaria Mahdjoub , an individual from Oran, Algeria.
Well, that will make the job of Romanian law enforcement a hell lot easier! gj!
Romania joins Poland :https://therecord.media/poland-pesel-system-state-registry-cyber-incident, Slovakia :https://www.finsider.sk/ekonomika/kataster-nehnutelnosti-celi-kybernetickemu-utoku-nezapinajte-pocitace-vyzvali-zamestnancov/, Greece :https://www.ktimatologio.gr/grafeio-tipou/deltia-tipou/1465, Morocco :https://www.moroccoworldnews.com/2025/06/206486/algerian-jabaroot-group-behind-cnss-breach-attacks-moroccan-property-registry/, Russia :https://meduza.io/en/news/2025/01/08/hackers-claim-breach-of-russia-s-real-estate-registry-leak-alleged-database-fragment, and Ukraine :https://komersant.ua/en/khakerska-ataka-na-derzhreiestry-chy-varto-pereviriaty-maynovi-prava/ as countries that had their land registry agencies hacked over the past three years.
In this edition of Seriously Risky Business , Tom Uren and James Wilson talk about different ways ransomware groups are taking advantage of AI. The relatively new FulcrumSec group uses simple techniques to breach companies and then uses AI to get more leverage over victims in its extortion negotiations.
Hugging Face hacked using AI: A threat actor used an autonomous AI agent to breach AI platform Hugging Face last week. The attacker used exploits in the platform's data-processing pipeline to pivot to some parts of the company's internal systems. Hugging Face says no customer data was exposed but the attacker stole internal datasets and some cloud credentials. Hugging Face says it tried to use a frontier AI model to analyze the hack but was blocked by its guardrails, which couldn't differentiate between an IR event and offensive operations. [ Hugging Face :https://huggingface.co/blog/security-incident-july-2026]
HuggingFace got hacked by an AI. What stuck out to me was the guardrail asymmetry. The attacker had no constraints, but HF's response ran afoul of the abuse guardrails, forcing them into an unplanned switch to local models. Another aspect for your IR plans. huggingface.co/blog/securit... [image or embed]:https://bsky.app/profile/did:plc:yfrzbyzye2ekirvpkzyemkxr/post/3mqujyw2ly52g?ref_src=embed
Coca-Cola hit by ransomware: Coca-Cola has suspended production at its Fairlife dairy subsidiary after a ransomware attack. In an SEC filing, Coca-Cola said hackers accessed Fairlife production-related systems this week. Production has been halted at Fairlife US factories. The company's Canadian production lines were unaffected. No ransomware group has taken credit for the incident, yet. [ SEC :https://www.sec.gov/Archives/edgar/data/21344/000162828026048466/ko-20260716.htm // TechCrunch :https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/]
KNPP leak: Threat intel analyst Rakesh Krishnan looks at a leak of sensitive files from India's KNPP nuclear power plant after one of its contractors got hit by the World Leaks extortion group. [ The Raven File :https://theravenfile.com/2026/07/17/kudankulam-nuclear-power-plant-leak-an-accidental-disclosure/]
Ostium crypto-heist: The Ostium DeFi platform was hacked for $18 million last week after hackers exploited its own price-reporting infrastructure. [ CoinDesk :https://www.coindesk.com/business/2026/07/15/ostium-suffers-usd18-million-exploit-as-oracle-attack-wave-continues-to-hit-defi]
Estée Lauder discloses Oracle EBS breach: Cosmetics giant Estée Lauder has confirmed that hackers stole customer data from its Oracle E-Business Suite platform last year. The company disclosed the breach to US state officials almost a year after it took place. This is Estée's second breach after another one in 2023. The Clop hacking group is behind the hacking spree that targeted Oracle EBS servers. [ California OAG :https://oag.ca.gov/ecrime/databreach/reports/sb24-626688]
Ernst & Young also discloses breach: Accounting and risk management giant Ernst & Young also disclosed a breach, but the disclosure has been so sanitized of any info that I can't tell what's this about. [ California OAG :https://oag.ca.gov/ecrime/databreach/reports/sb24-626542]
DigiCert breach linked to CylindricalCanine: Security firm Expel has linked the hack of certificate authority DigiCert to CylindricalCanine, a sub-group of GoldenEyeDog, a financially motivated group operating out of China. [ Expel :https://expel.com/blog/introducing-cylindricalcanine/]
Ofcom opens TikTok inquiry: The UK's communications watchdog has opened a formal investigation into TikTok for failing to protect children from harmful content on the platform, as per the UK's Online Safety Act. [ Ofcom :https://www.ofcom.org.uk/online-safety/protecting-children/investigation-into-tiktoks-compliance-with-duties-to-protect-children-from-encountering-harmful-content-under-section-12]
Moonshot releases Kimi K3: Chinese AI startup Moonshot has unveiled a new AI model named Kimi K3, which the company claims can rival the ones from top American firms like Anthropic and OpenAI. [ Kimi :https://www.kimi.com/blog/kimi-k3 // Business Insider :https://www.businessinsider.com/kimi-k3-ai-model-moonshot-china-open-weights-benchmarks-pricing-2026-7]
Rust in Chromium: Microsoft is working on adding a Rust-based PNG image decoder in the Chromium browser project, a more secure component for processing PNG images for Chrome, Edge, Opera, and other similar browsers. [ Microsoft :https://microsoftedge.github.io/edgevr/posts/Rustifying-Image-Codecs-in-Chromium/]
EU password manager has ties to Russia: An investigation has revealed that Spain-based password manager Passwork shares its codebase and a "near-identical user manual" with a similarly-named password manager advertised in Russia. The Spanish version has allegedly been receiving software updates from an UAE firm managed by one of Passwork's Russian co-founders. The Spanish Passwork's customer list includes European government agencies and universities, which raises concerns of espionage. [ OCCRP :https://www.occrp.org/en/investigation/european-password-manager-shares-origins-and-updates-with-state-certified-russian-firm]
India fines HP over cartel practices: The Indian government fined HP $14.4 million over cartel practices after the company colluded with resellers to fix prices for ink cartridges, toner, and other printing supplies in government contract bids. [ ArsTechnica :https://arstechnica.com/gadgets/2026/07/hp-fined-1-4-billion-rupees-for-cartelization-of-ink-cartridges-toner-pcs/]
SanFran CAO cracks down on nudify apps: The San Francisco City Attorney's Office has sent cease-and-desist letters to Apple and Google and ordered the tech giants to remove AI nudify apps from their stores and stop indirectly profiting from CSAM. [ WIRED :https://www.wired.com/story/san-francisco-demands-apple-and-google-delete-ai-nudify-apps-from-app-stores/]
Morocco confirmed as NSO customer: A whistleblower and former member of Morocco’s domestic intelligence service has confirmed their government's access to the NSO Pegasus spyware, contrary to the government's past public denials. The tool was heavily used to spy on dissidents, journalists, and even politicians abroad. [ OCCRP :https://www.occrp.org/en/project/the-pegasus-project/moroccan-government-used-powerful-israeli-pegasus-spyware-to-hack-phone-of-journalist-former-intelligence-officer-says // Forbidden Stories :https://forbiddenstories.org/codename-morgan-a-look-back-at-moroccos-acquisition-of-pegasus-involving-israel-and-the-united-arab-emirates/]
UK scraps digital ID scheme: The UK government will scrap a proposed digital ID scheme once its new prime minister Andy Burnham takes office on Monday. The scheme was announced last September and was supposed to enter into effect next year. It involved issuing a digital ID for UK citizens and legal residents in the form of a mobile app. The ID was meant to serve as proof for the Right to Work in the UK. [ Reuters :https://www.reuters.com/world/uk/next-uk-prime-minister-andy-burnham-drops-digital-id-scheme-2026-07-18/]
US govt fails to rotate cyber personnel: The US government failed to follow through with one of its own programs to rotate cybersecurity employees between federal agencies. Only eight employees participated in the program since 2022. The program was meant to teach employees new skills before returning to their native agencies. [ GAO :https://www.gao.gov/products/gao-26-108736 // Cyberscoop :https://cyberscoop.com/opm-federal-rotational-cyber-workforce-program-gao/]
White House announces Gold Eagle program: The Trump administration has launched a new program to help coordinate the disclosure and patching of vulnerabilities in open-source projects and critical infrastructure. The new Gold Eagle program was designed to receive bug reports at scale, usually found using AI tools and frontier AI models. CISA, the Treasury Department, and the Pentagon are involved in the program. [ White House :https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/]
France bans Polymarket: The French government has ordered internet service providers to block access to prediction market betting platform Polymarket. The French regulatory authority formally banned the platform in 2024 and threatened fines of up to €200,000 for French citizens placing bets on the platform. The agency moved into active enforcement after data showed Polymarket's userbase grew in France despite the ban. Spain also banned Polymarket in May. [ Engadget :https://www.engadget.com/2218130/france-doubles-down-on-restricting-access-to-polymarket/]
In this Risky Business sponsor interview , Casey Ellis chats with Haroon Meer from Thinkst about building companies customers don’t hate. Haroon explains why Thinkst still offers Canary tokens for free and why it has avoided annual price hikes on its paid products. They talk about Eric Ries’s “Incorruptible”, Rob Lee’s 100-year-company approach at Dragos, and why keeping customers happy is a better business strategy than chasing easy sugar highs.
Graykey maker sues employee for leaking exploit: Graykey-maker Magnet Forensics has sued a former employee for allegedly leaking details about a proprietary iPhone exploit. Magnet claims Mario Del Gaudio shared details of the exploit with his new employer and rival company Paradigm Shift. The exploit was tracked internally at Magnet as MSG but was disclosed publicly by Paradigm Shift in a blog post as usbliter8. The exploit allows attackers to run malicious code inside the SecureROM of Apple devices using A12 and A13 chips. It is a hardware bug and unpatchable. [ Bloomberg :https://www.bloomberg.com/news/articles/2026-07-17/iphone-hacking-firm-sues-ex-worker-over-alleged-theft-of-secrets // CourtListener :https://www.courtlistener.com/docket/73584326/magnet-forensics-llc-v-del-gaudio/ // usbliter8 blog post :https://ps.tc/pages/blog-usbliter8.html]
TfL hackers get five years: A UK judge has sentenced two members of the Scattered Spider hacking group to 5.5 years in prison each. Thalha Jubair and Owen Flowers pleaded guilty last month to hacking the London public transport authority in August of 2024. The hack caused months of disruptions at Transport for London and caused damages of £39 million. Jubair is also charged in the US with hacking and extorting 47 US companies and allegedly seeking ransoms of at least $115 million. [ NCA :https://www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever-cyber-crime-case]
REvil hacker arrested in Armenia: Armenian authorities have arrested a suspected member of the REvil ransomware group. Alexander Ermakov was arrested at the Yerevan airport at the end of June on an Interpol arrest warrant. A man named Alexander Ermakov is the main suspect behind the ransomware attack on Australia's Medibank insurer in 2022. Russian media claims that Armenian authorities arrested a man with the same name and that the real Ermakov is in Russia, where he is serving a restriction of freedom sentence that prevents him from traveling abroad. [ RIA Novosti :https://ria.ru/20260716/armenija-2105285622.html // Risky Business :https://risky.biz/au-uk-us-sanction-russian-behind-medibank-hack/]
Scam center dismantled in Timor-Leste: Police in Timor-Leste have raided three cyber scam compounds in the capital city of Dili. Police arrested 253 suspects, with most being Chinese and Indonesian nationals. Authorities also raided another compound last month. [ ABC :https://www.abc.net.au/news/2026-07-15/timor-scam-compound-chinese-indonesians-cambodians-arrested/106913210]
DHS seizes 30,000 mobile SIM cards: The DHS Homeland Security Investigations seized more than 30,000 mobile SIM cards in June and July as part of a crackdown against telephone fraud. [ Bloomberg :https://www.bloomberg.com/news/articles/2026-07-16/dhs-seizes-30-000-mobile-sim-cards-in-effort-to-stop-phone-fraud]
GTA hacker released from hospital, sent to prison: A member of the Lapsus$ hacking group has been released from a secure hospital and transferred to a normal prison in the UK. Arion Kurtaj is set to face trial again for hacking Rockstar Games in 2022 and releasing GTA5 source code and GTA6 gameplay. Kurtaj was diagnosed with severe autism and sentenced to an indefinite hospital order in December 2023. [ GameRant :https://gamerant.com/gta-6-hacker-trial-november/ // Polygon :https://www.polygon.com/gta-6-leak-hacker-what-happened-trial-burner-phone-selfies-hospital/]
UAT-11795 profile: Cisco is tracking a new e-crime group targeting companies in the US and Europe with the Starland RAT and a command-and-control (C2) memory implant named the WLDR Agent. [ Cisco Talos :https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/]
TAG-150 evolution: eSentire has published details on the changes to the tradecraft of TAG-150, an e-crime group behind the CastleLoader, CastleBot, and CastleRAT malware strains—also tracked as DinDoor, a Deno-based loader, NightshadeC2, and DenoRAT, a Deno-based Remote Access Trojan (RAT). The biggest change is their adoption of ClickFix, everyone's favorite infection vector. [ eSentire :https://www.esentire.com/blog/dindoor-denorat-and-nightshadec2-analyzing-tag-150s-evolving-tradecraft]
More ViPNeT exploitation in Russia: A hacking group is planting backdoors inside Russian companies using the ViPNet enterprise VPN software. The attackers first compromise one VPN node and then exploit the software's update mechanism to install the backdoor on the whole network. ViPNet owner Infotecs has confirmed the attacks and released security updates. A similar wave of attacks also took place in April last year. [ Infotecs :https://infotecs.ru/press-center/publications/razyasneniya-kompanii-infotecs-po-intsidentu-svyazannomu-s-rasprostraneniem-vredonosnogo-po/ // PositiveTechnologies :https://habr.com/ru/companies/pt/articles/1060016/ // Kaspersky :https://securelist.com/tr/hellonet-vipnet/120700/ // Last year's attacks :https://securelist.ru/new-backdoor-mimics-security-software-update/112326/]
Scarcity scams are here to stay: Scarcity scams are a new category of online scams where threat actors run fake sites for online services with limited availability or spots. This type of scam has exploded across the past few years and typically target the reservation sites of various government websites across the world. [ DomainTools :https://dti.domaintools.com/securitysnacks/scarcity-scams]
Sextortion campaigns: A recent spike in sextortion email scams has been linked to the good ol' Trik/Phorpiex botnet, which is still alive after all these years. [ PointWild :https://www.pointwild.com/threat-intelligence/phorpiex-inside-the-botnet-powering-global-sextortion-spam-operations/]
Text salting in the wild: Threat actors are using a technique named "text salting" to hide text inside their emails and bypass email spam filters for both traditional and AI-powered email security systems. Barracuda has seen the technique used in over a million retail-themed phishing scams. [ Barracuda :https://blog.barracuda.com/2026/07/16/text-salting-ai-email-security]
RubyGems malware: At least two dormant RubyGems accounts have been compromised to push malware to old projects. [ Aikido Security :https://www.aikido.dev/blog/sleepergem-rubygems-supply-chain-attack // Step Security :https://www.stepsecurity.io/blog/sleepergem-compromised-rubygems-drop-persistent-backdoor]
OAuth Client ID Spoofing: Threat actors are using OAuth client ID spoofing to abuse Microsoft Entra ID for account enumeration, check password validity, and account state. The technique is seeing increased usage, per Proofpoint. [ Proofpoint :https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy]
Proofpoint observed two independent campaigns adopting this tradecraft: • UNK_PyReq2323: >1M targeted users, 700K+ spoofed client IDs • UNK_OutFlareAZ: >2M targeted users, 3.7M spoofed client IDs Different tooling and infrastructure suggest growing adoption.
XZ Utils backdoor: Adrian Mastronardi has published a book with the in-depth story of the XZ Utils backdoor incident from 2024. [ Half a Second :https://www.half-second.com/]
Pegasus spyware: The security team at Amnesty International has published the most comprehensive analysis of the Pegasus spyware to date, leveraging the insights from past reports and the recent WhatsApp lawsuit. [ Amnesty International :https://securitylab.amnesty.org/latest/2026/07/inside-pegasus-the-evolution-of-the-worlds-most-notorious-spyware/]
ClickLock Stealer: A new infostealer targeting macOS users has been spotted in the wild. This one has been named ClickLock because it blends ClickFix and locker tactics for its distribution and installation process. [ Group-IB :https://www.group-ib.com/blog/clicklock-stealer-macos-malware/]
CrashStealer: There's also another macOS infostealer in the wild, named CrashStealer because it tries to impersonate Apple's crash-reporting framework to harvest browser credentials, cryptocurrency wallets, and keychain data. [ Jamf :https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/]
ACR Stealer: Microsoft has reported an increase in attacks deploying the ACR Stealer across customer environments since April. [ Microsoft :https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/]
BoryptGrab: Almost 300 GitHub repositories impersonating legitimate software were actually spreading a version of the BoryptGrab infostealer. [ Arctic Wolf :https://arcticwolf.com/resources/blog/fake-github-repositories-deliver-boryptgrab-lineage-infostealer/]
TELEPUZ: Elastic has spotted a new malware framework being deployed in the wild that appears to be related to an upcoming MaaS. [ Elastic :https://www.elastic.co/security-labs/telepuz-maas-malware-clickfix]
Spirals ransomware: Broadcom's Symantec team has spotted a new ransomware strain named Spirals being deployed in Asia. Not much information about it so far. [ Broadcom :https://www.security.com/threat-intelligence/ransomware-spirals-extortion]
NadMesh botnet: A newly discovered botnet is specifically targeting AI infrastructure and the MCP ecosystem. The NadMesh botnet has targeted Ollama, ComfyUI, and other AI-related servers since early July. The botnet plants SSH backdoors for control and future access. According to Chinese security firm QiAnXin, the botnet appears to be an "industrial-grade" operation with a "clear commercial intent." [ QiAnXin :https://blog.xlab.qianxin.com/nadmesh-botnet-analysis-a-product-grade-threat-for-the-ai-service-era-en/]
OkoBot framework: Researchers have found a new modular malware framework named OkoBot that resembles an infostealer but puts more focus on stealing sensitive data from cryptocurrency owners and related services. [ Kaspersky :https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660/]
WackoGinx phishing kit: Researchers have found a new phishing kit named WackoGinx (also WachoGinx) that can run campaigns targeting M365, Facebook, Gmail, LinkedIn, and PayPal. [ Threatactix :https://threatactix.com/2026/07/02/a-rare-look-inside-the-command-and-control-panel-behind-modern-phishing-operations/]
In this Soap Box edition of the podcast, Patrick Gray chats with Thinkst Canary founder Haroon Meer about his "decade of deception."
UTA0533 is behind new SonicWall zero-day wave: A hacking group tracked as UTA0533 is behind two zero-days exploited in SonicWall SMA appliances. The zero-days include an SSRF and a code injection vulnerability that grant the group root-level access to the device. The attacks began in late June and are deploying malware designed specifically for SonicWall SMA VPN appliances. SonicWall released patches for both zero-days last week. [ Volexity :https://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/ // SonicWall patches :https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008]