Lizzie Clark

July 21st – This Week’s Top Cybersecurity and Dark Web Stories

This week’s cybersecurity and dark web news stories discuss w2pshell: Pre authentication RCE in WordPress core, hacker wiping Romania’s entire land registry database, and the state of ransomware in 2026.

Millions of WordPress Sites at Risk as Hackers Exploit WP2Shell Vulnerabilities

Last week, WordPress patched two critical security flaws – tracked together as WP2Shell – and enabled forced automatic updates where possible. Within days, multiple cybersecurity firms including Patchstack, Hexastrike, and WatchTowr confirmed active exploitation in the wild.

One of the vulnerabilities was discovered and reported by Searchlight Cyber. Paired together, the two bugs allow attackers to take full remote control of vulnerable websites without needing any prior authentication. The affected versions span WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.

Quantifying the exposure is difficult, but the numbers are sobering. WordPress’ own statistics show more than 400 million websites running affected versions globally, though that figure doesn’t account for sites already patched since the disclosure. Cybersecurity consultant Daniel Card sampled around 4,200 WordPress websites and estimated that fewer than 15% remain vulnerable, but even applying that conservative fraction to the total WordPress population yields a figure in the millions.

Some mitigations are already in place: Cloudflare has been blocking attacks against vulnerable sites, and forced automatic updates will have reached many managed installations. The risk is concentrated among self-hosted or unmanaged sites whose administrators haven’t yet applied the patch. If your site runs WordPress, check the version number today. The fix is available and the window for exploitation is open.

Romania’s Entire Land Registry Wiped After Attacker’s Extortion Demand Is Refused

On July 14, a threat actor identified as ByteToBreach gained access to the systems of Romania’s National Agency for Cadastre and Real Estate Advertising (ANCPI) using valid credentials, mapped the internal network, attempted to extort the agency, and – when demands were refused – wiped both the production database and its backups. The country’s entire land registry was gone.

The attack brought Romania’s real estate sector to an immediate halt. Official applications, websites, and email servers all went offline. Notaries and citizens lost access to property records overnight. By July 15, stolen data – including employee credentials, internal documents, and IT network details – was posted for sale on a hacking forum. The agency’s website remained offline for at least a week, with officials announcing a full network rebuild. Recovery has been made possible by the existence of an offline backup, which prevented what could have been a permanent loss of national records.

The same actor previously breached Sweden’s e-government portal earlier in 2026 and has a documented pattern of targeting government agencies: credential-based entry, internal reconnaissance, data exfiltration, extortion, and destruction if payment is withheld. No malware or custom tooling was identified – the attack relied entirely on manual actions executed through legitimate, stolen credentials.

The incident sits within a wider pattern. Similar attacks on land registry agencies have been recorded in Poland, Slovakia, Greece, Morocco, Russia, and Ukraine over the past three years, pointing to sustained, sector-specific targeting of property record infrastructure across Europe and beyond. For any organisation holding critical national records: offline backups are not optional, and credential monitoring is not a luxury.

The State of Ransomware in 2026

Sophos has published its seventh annual State of Ransomware report, drawing on survey responses from 2,158 IT and cybersecurity leaders across 17 countries whose organisations were hit by ransomware in the past year. The headline finding is genuinely mixed: meaningful progress on some fronts, worrying reversals on others.

The good news is real. Median ransom demands have fallen 65% over two years, from $2 million in 2024 to $698,000 this year. Median payments have dropped to $769,000, with just over half of paying organisations successfully negotiating below the initial demand. Backup-based recovery surged to 66% of encrypted-data incidents, a 12-point jump from last year, suggesting organisations have meaningfully reinvested in resilience infrastructure. And the proportion of attacks where exploited vulnerabilities served as the entry point fell sharply – from 32% to 18% – indicating that sustained patching investment is having a measurable effect.

The uncomfortable truths are equally clear. Encryption success is rising again: 56% of attacks succeeded in encrypting data, up from 50% last year, reversing two years of progress. Recovery costs have climbed to an average of $1.7 million per incident, excluding any ransom paid. And the attack vector that has stepped in to replace vulnerability exploitation is email – phishing (24%) and malicious email (26%) now account for half of all ransomware root causes, making inbox security the most urgent defensive priority.

Perhaps the most striking finding is the role of identity compromise. Two-thirds of ransomware victims confirmed that their ransomware incident was also their most significant identity attack of the year. Crucially, 97% of organisations where compromised credentials were the root cause had MFA enabled at the time – meaning MFA, while necessary, is no longer sufficient. Attackers have developed enough bypass techniques that organisations treating MFA as their primary credential defence are operating on borrowed time.

The human cost is also documented. Among IT and cybersecurity teams at organisations whose data was encrypted, 99% reported lasting repercussions: increased anxiety and stress, pressure from senior leaders, and in 21% of cases, a change in leadership as a direct result of the attack. The one bright spot on the human side is a rise in executive recognition – up 5 points year-on-year – which Sophos suggests may itself be driving some of the positive operational trends elsewhere in the data.