Romania Land Registry Cyberattack, CRA Standards, Wallix Funding, & N. Korea Supply-Chain Threats

ROMANIA LAND REGISTRY DISRUPTED BY CYBER ATTACK

cyberattack wiped Romania’s land registry database, disrupting real estate transactions nationwide after the hack destroyed production systems and backups following a failed extortion attempt. According to experts, the attack, which began July 14, points to a threat actor known as ByteToBreach. The attacker apparently gained access using valid credentials, allowing it to bypass perimeter defenses before conducting reconnaissance across the agency’s network. After mapping internal systems, the attacker deleted critical data and disabled key services, including the land registry database, official applications, websites and email servers. The outage prevented notaries, government officials and citizens from accessing essential property records, effectively bringing Romania’s real estate market to a standstill.

Reports said the attacker also stole sensitive information, including employee credentials, internal documents and network details, before offering the stolen data for sale on a hacking forum. The destructive actions followed an unsuccessful attempt to extort the agency. Romanian authorities have begun rebuilding the affected infrastructure using an offline backup.

CYBER RESILIENCE ACT: CENELEC, THE PROFESSIONAL ORGANIZATION, READY TO FINALIZE THE STANDARD IN VULNERABILITY HANDLING
 
CRA Vulnerability Handling standard sent out for final internal review by JTC13/WG9.
The past weeks CEN-CENELEC JTC13/WG9 worked very hard to complete the prEN 40000-1-3, the Cyber Resilience Act standard for vulnerability handling (Annex I, Part II), or PT3 as we call it internally. 
On the 16th and 17th of July JTC13/WG9 was kindly hosted by the Eindhoven University of Technology for an extra hybrid meeting for which I especially want to thank Harold Weffers, EngD well known to the ECA !
for the great hospitality. 
 
Now the document is sent out for a final internal review by JTC13/WG9 (N858) to discuss and address any last comments on the 31st of July after which it will be provided to the European Commission for their review.
 
WALLIX SECURES AN ADDITIONAL FUNDING
WALLIX, a leading European company in Identity and Access management, is already listed on EURONEXT. Nevertheless, a set of private investors has accepted to increase their support by providing an additional non diluting funding of 25 M€ in debt and bonds, this amount can be increased up to 65 M€.
 
NORTH KOREA REPORTED TO LAUNCH ATTACKS AGAINST FREQUENTLY USED SOFTWARE TOOLS 
(Tribute to DATABREACHTODAY ENEWS)

Hackers have been intensifying supply-chain attacks by compromising open-source software hosted on repositories, including npm for JavaScript packages and PyPi for Python libraries, at least since early 2024, when a nation-state compromised data compression software XZ Utils. Amazon now says it believes with medium confidence that the same financially motivated Pyongyang actor commonly tracked as Sapphire Sleet or Stardust Chollima is behind the compromise of JavaScript packages Axios, Debug, Chalk and Typo-Crypto. Amazon makes the assessment of North Korean responsibility with high confidence. It’s only whether the same Pyongyang threat actor was involved in all four cases that needs independent verification, said CJ Moses, vice president of Amazon engineering. 

Share:

More Posts