Newsletters

Written content from the Risky Business Media team

Risky Bulletin: New Chinese cyber contractor identified

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The cyber sleuths at Intrusion Truth have uncovered a new secretive Chinese IT company that appears to work as a cyber contractor and tool developer for Chinese state-sponsored hacking operations.

Online clues appear to suggest that Guangdong Chanming appears to have developed RedRelay (aka ORBWEAVER), an ORB network (aka proxy botnet) that was used by almost a dozen Chinese APT groups to hide the origin of their attacks.

The list includes the likes of APT15, Red Vulture, Ke3chang, Vixen Panda, Playful Dragon, Nylon Typhoon, and others.

Risky Bulletin: A JSON RCE bug is about to rock the Java world

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Threat actors are exploiting a vulnerability in Alibaba's Fastjson, one of the Java ecosystem's most popular libraries for working with JSON-formatted data.

Active exploitation began last week, a day after details about the security flaw were revealed by cybersecurity firm FearsOff.

The attacks, first spotted and documented by Imperva and ThreatBook, target CVE-2026-16723, a vulnerability that can enable unauthenticated remote code execution attacks against Java projects that use the Fastjson library as a component.

Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Cybersecurity and intelligence agencies from multiple Western countries have issued joint security advisories on Thursday warning of a major Russian hacking campaign that's targeting Zimbra email servers.

The attacks have been going on since last year. The zero-day, tracked as CVE-2025-66376, was patched in November but attacks have been traced back to at least July.

The zero-day itself is a stored cross-site scripting (XSS) bug that allows the attackers to load malicious code inside a Zimbra webmail client via the CSS @import feature. The malicious code would load a web tool called Ulej (Russian for Beehive) that could be used to harvest credentials, session tokens, backup 2FA codes, browser-saved passwords, and the contents of the victim’s mailbox going back 90 days.

Srsly Risky Biz: Knives Are Out For Open-Weight AI Models

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

Both the American and Chinese governments have signalled they plan to rein in open-weight AI models. 

The Trump administration seems certain to add some Chinese technology companies to the Entity List to protect investment in American frontier AI models. Meanwhile, Beijing is apparently weighing applying export restrictions on Chinese AI tech, including open-weight models.

Overnight, different US government officials issued a strong, coordinated signal that they plan to take action against Chinese AI companies. Michael Kratsios, the director of the White House's Office of Science and Technology Policy, wrote on X that Chinese company Moonshot AI had "developed a sophisticated internal platform to conduct large scale distillation against US models" and that "large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable."

Risky Bulletin: Linux kernel discloses 442 CVEs as AI bugpocalypse settles in

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The Linux kernel project has disclosed 442 vulnerabilities over the past three days, in a massive dump of CVEs on its security mailing list.

Although not confirmed, the bugs were likely discovered using AI tools. Over the past months, projects like Anthropic's Glasswing and OpenAI's Daybreak have been granting access to advanced frontier cybersecurity models to top-tier security firms and researchers to find bugs with AI in major open-source projects.

Most of the bugs are low-severity issues, so nothing world-ending for the internet today.

Risky Bulletin: Hacker wipes Romania's entire land registry database

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

A hacker has breached Romania's cadastre agency and wiped the country's entire land registry database following a failed extortion attempt.

The hack has brought Romania's entire real-estate market to a standstill as official apps and websites have been offline for a week. Notaries can't record new transactions while citizens can't obtain proof of ownership or detailed land records.

Email servers at the National Agency for Cadastre and Real Estate Advertising (Agenția Națională de Cadastru și Publicitate Imobiliară, or ANCPI) were also down as part of the incident.

Srsly Risky Biz: Ransomware Uses AI To Amp Up Negotiations

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

It's commonly thought that ransomware operators are simply using AI to hack more companies. However, some operators are employing AI to generate leverage so they can extract more money in negotiations with victims. 

A leading example is FulcrumSec, a data extortion group that started operating around September 2025 and uses simple techniques to breach organisations. It typically gains access by taking advantage of hardcoded or exposed credentials, unpatched applications or misconfigured storage. 

The group claims to have breached 25 organisations and stolen several terabytes of data using these techniques. 

Risky Bulletin: India bans app used to hack e-rickshaws in viral videos

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The Indian government has ordered Apple and Google to remove a battery management app from their stores that had been used over the past weeks to hack e-rickshaws across the country as part of a toxic viral trend that mocked drivers and risked blocking traffic.

Videos of the hacked have been spreading on social media for two-three weeks in a trend named the Tirri Challenge.

The videos showed distressed drivers stuck in traffic pushing their vehicles to the side or crying over lost revenue on the phone with family and mechanics.

Srsly Risky Biz: Supreme Court Undermines Section 702

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

A new US Supreme Court decision could undermine the flow of Section 702 intelligence collection from Europe.

Section 702 allows the US government to collect intelligence on people outside the US with compelled help from communication service providers and is regarded as the crown jewel of American foreign intelligence collection. 

Since 2000, successive data sharing agreements have facilitated transatlantic commerce by allowing the legal transfer of personal data from the EU to the US. Section 702 collection from Europe relies on these data flows and the intelligence program has been at the heart of legal challenges to the data sharing agreements. 

Risky Bulletin: All new cars to include a camera aimed at the driver's face

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

All new cars manufactured and sold in the EU and in the US will have to include a mandatory infrared camera aimed at the driver's face at all times, which is alarming some privacy groups.

The infrared camera will track the driver's head position and eye movements and then alert distracted drivers if their eyes go off the road.

The new regulation has entered into effect in the EU on Monday and will enter into effect next year in the US. In the EU, the new camera requirement is part of the block's second General Safety Regulation (GSR2), a broader swath of new safety rules introduced for the auto industry and designed to improve road safety.