>

Marriott’s Second Breach: 5.2 Million Guest Records Exposed

At the end of March 2020, Marriott disclosed its second major breach in two years: the login credentials of two franchise properties had been abused in late February 2020 to siphon 5.2 million guest records, including names, addresses, phone numbers, birthdays, loyalty details, and in some cases travel itineraries and room preferences. Unlike the 2018 Starwood catastrophe that exposed up to 383 million records, this intrusion was caught and contained within weeks, but it reignited regulatory scrutiny on both sides of the Atlantic. This retrospective covers the intrusion path, the data involved, the disclosure timing, and the aftermath for one of hospitality's biggest names.

Continue ReadingMarriott’s Second Breach: 5.2 Million Guest Records Exposed

When Hackers Hunted the WHO: Cyberattacks in a Pandemic’s First Weeks

On 24 March 2020, Reuters reported that hackers had stood up a near-identical malicious imitation of the World Health Organization's internal email portal, infrastructure aimed at stealing passwords from staffers coordinating the global pandemic response. The same reporting documented that around 450 active WHO email addresses and passwords, plus thousands more belonging to people working on the COVID-19 response, had been leaked online. It was not an isolated incident but part of a documented surge in targeting of health bodies that spring. This piece reconstructs the verified incidents of March 2020 and the wider lesson that crisis response organizations are priority intelligence targets.

Continue ReadingWhen Hackers Hunted the WHO: Cyberattacks in a Pandemic’s First Weeks

The FBI’s COVID-19 Warning: IC3 and the Scam Surge of March 2020

On 20 March 2020, the FBI's Internet Crime Complaint Center published a public service announcement warning that cyber criminals were exploiting the COVID-19 pandemic at scale: phishing lures referencing stimulus payments and fake cures, malicious apps, and infrastructure spoofing health authorities. It was one node in a broader wave of official guidance that spring, with CISA and the UK's NCSC issuing joint advice on pandemic-era remote work and video conferencing security, and IC3's later reporting would show complaint volumes surging through 2020. This retrospective explains what the warning said, what the threat landscape actually looked like that spring, and how a global crisis became an attack-surface multiplier.

Continue ReadingThe FBI’s COVID-19 Warning: IC3 and the Scam Surge of March 2020

SMBGhost CVE-2020-0796: Wormable Code in Windows 10 SMBv3

On 11 March 2020, Microsoft shipped a fix for CVE-2020-0796, a wormable remote code execution flaw in how Windows 10 and Windows Server handle compressed SMBv3 packets. An attacker could send a specially crafted compressed packet and trigger a buffer overflow before authentication, exactly the class of bug security people fear could be chained into self-spreading malware. Researchers named it SMBGhost, published proof-of-concepts within days, demonstrated local privilege escalation chains, and Microsoft followed with an out-of-band patch update on 12 March. This technical retrospective covers the flaw mechanics, the compression workaround, the patch wave, and why the wormable nightmare never fully materialized.

Continue ReadingSMBGhost CVE-2020-0796: Wormable Code in Windows 10 SMBv3

Virgin Media 2020: 900,000 People in an Unsecured Marketing Database

On 28 February 2020, Virgin Media confirmed that a marketing database containing the personal details of around 900,000 people had been left insecure and accessible online, discovered not by criminals but by a researcher during unrelated work. The dataset, stored on an unsecured cloud instance, included names, home and email addresses, and phone numbers, and had been reachable for at least ten months. This post explains exactly what was exposed, how the misconfiguration happened, how Virgin Media responded, and what happened next: a textbook non-hack data breach that still required full disclosure, notification, and regulatory scrutiny.

Continue ReadingVirgin Media 2020: 900,000 People in an Unsecured Marketing Database

Clearview AI in 2020: Three Billion Scraped Faces, One Leaked Client List

In late February 2020, facial recognition startup Clearview AI confirmed that a misconfigured server had exposed its entire client list, days after a major newspaper investigation revealed the company had scraped more than three billion facial images from social networks and the open web to sell face search to police. The leaked list showed U.S. retailers, banks, and investors among users of a tool built on photos most people never knowingly gave. Cease-and-desist letters from Facebook and other platforms followed, along with GDPR complaints across Europe. This is how facial recognition's most aggressive company lost control of its own story in a matter of weeks.

Continue ReadingClearview AI in 2020: Three Billion Scraped Faces, One Leaked Client List

Ransomware at a Gas Compression Facility: CISA’s OT Alert

On 20 February 2020, CISA published AA20-030A, a joint advisory describing how ransomware had disrupted a natural gas compression facility: a phishing link let commodity ransomware spread from IT into the OT network, encrypting data historians and polling servers, severing HMI visibility, and leaving operators blind to real-time pressure and flow data for two days. The advisory became a reference model for oil and gas asset owners because it mapped, step by step, how a single email chained into loss of operational visibility without directly controlling pipeline equipment. This retrospective walks through the kill chain, the defensive gaps, and the guidance that followed.

Continue ReadingRansomware at a Gas Compression Facility: CISA’s OT Alert

Exchange CVE-2020-0688: A Default Key Made Every Server Alike

On 11 February 2020, Microsoft disclosed CVE-2020-0688, a remote code execution vulnerability in Microsoft Exchange Server's Unified Messaging service that scored 9.8 on CVSS because every installation shipped with the same cryptographic validation key by default. Any authenticated user could send a specially crafted viewstate to the Exchange Control Panel and achieve RCE as SYSTEM, and because service accounts and weak credentials were everywhere, authenticated was a low bar. This analysis walks the vulnerable request path, the viewstate forgery mechanics, the patch, and the long tail of scanning and exploitation that followed for months.

Continue ReadingExchange CVE-2020-0688: A Default Key Made Every Server Alike

Internet Explorer CVE-2020-0674: The Zero-Day Advisory That Opened 2020

On 17 January 2020, Microsoft published ADV200001, a rare out-of-band advisory for CVE-2020-0674, a remote code execution flaw in the scripting engine used by Internet Explorer 9 and 11 that the company confirmed was being exploited in limited targeted attacks. There was no patch yet, only mitigations and workarounds, and defenders spent nearly a month exposed until the 11 February 2020 cumulative update shipped the fix. This piece reconstructs the advisory, the memory-corruption mechanics in the script engine, why IE was still a live attack surface in 2020, and what the episode taught about mitigations-first disclosure.

Continue ReadingInternet Explorer CVE-2020-0674: The Zero-Day Advisory That Opened 2020

CurveBall CVE-2020-0601: Forging Trust With One Elliptic Curve Parameter

On 14 January 2020, Microsoft's first Patch Tuesday of the decade included a fix for CVE-2020-0601, a cryptographic implementation flaw in Windows CryptoAPI reported to the vendor by the U.S. National Security Agency. The bug let anyone forge TLS certificates that appeared to chain to the U.S. government's ECC trusted root, making malicious HTTPS sites look legitimately signed. Researchers named it CurveBall, proof-of-concept exploits appeared within days, and CISA issued Emergency Directive 20-02 ordering federal agencies to hunt and patch. This is the story of how a single mishandled curve parameter undermined certificate trust Windows-wide.

Continue ReadingCurveBall CVE-2020-0601: Forging Trust With One Elliptic Curve Parameter

After Soleimani: The January 2020 US-Iran Cyber Alert Wave

Within hours of the 3 January 2020 strike that killed Iranian general Qasem Soleimani, security agencies on both sides of the Atlantic braced for cyber retaliation. On 6 January 2020 a U.S. federal website, the Federal Depository Library Program, was defaced with pro-Iran messaging and an image of a bloodied President Trump, claimed by a group calling itself Iran Silk Hat, while CISA and the FBI renewed warnings about possible Iranian attacks on critical infrastructure. This retrospective maps the verified incidents of that week, separates hype from evidence, and explains why agencies treated the moment as a genuine escalation trigger despite limited actual damage.

Continue ReadingAfter Soleimani: The January 2020 US-Iran Cyber Alert Wave

Travelex Ransomware 2020: When Sodinokibi Crippled a Currency Giant

On 31 December 2019, foreign exchange giant Travelex took its UK and international websites and mobile apps offline following a cyberattack, an outage that also knocked out white-label travel money services at ASDA, Tesco and Sainsbury's overnight. When the story became public on 7 January 2020, the criminals behind Sodinokibi (REvil) ransomware were demanding 4.6 million pounds, claiming to have copied more than 5GB of customer data, and the company would spend weeks rebuilding systems by hand. This account reconstructs the verified timeline, the double-extortion playbook, and how the incident contributed to an August 2020 administration that cut more than a thousand UK jobs.

Continue ReadingTravelex Ransomware 2020: When Sodinokibi Crippled a Currency Giant
>