>

Internet Explorer CVE-2020-0674: The Zero-Day Advisory That Opened 2020

On 17 January 2020, Microsoft published ADV200001, a rare out-of-band advisory for CVE-2020-0674, a remote code execution flaw in the scripting engine used by Internet Explorer 9 and 11 that the company confirmed was being exploited in limited targeted attacks. There was no patch yet, only mitigations and workarounds, and defenders spent nearly a month exposed until the 11 February 2020 cumulative update shipped the fix. This piece reconstructs the advisory, the memory-corruption mechanics in the script engine, why IE was still a live attack surface in 2020, and what the episode taught about mitigations-first disclosure.

Continue ReadingInternet Explorer CVE-2020-0674: The Zero-Day Advisory That Opened 2020

CurveBall CVE-2020-0601: Forging Trust With One Elliptic Curve Parameter

On 14 January 2020, Microsoft's first Patch Tuesday of the decade included a fix for CVE-2020-0601, a cryptographic implementation flaw in Windows CryptoAPI reported to the vendor by the U.S. National Security Agency. The bug let anyone forge TLS certificates that appeared to chain to the U.S. government's ECC trusted root, making malicious HTTPS sites look legitimately signed. Researchers named it CurveBall, proof-of-concept exploits appeared within days, and CISA issued Emergency Directive 20-02 ordering federal agencies to hunt and patch. This is the story of how a single mishandled curve parameter undermined certificate trust Windows-wide.

Continue ReadingCurveBall CVE-2020-0601: Forging Trust With One Elliptic Curve Parameter

After Soleimani: The January 2020 US-Iran Cyber Alert Wave

Within hours of the 3 January 2020 strike that killed Iranian general Qasem Soleimani, security agencies on both sides of the Atlantic braced for cyber retaliation. On 6 January 2020 a U.S. federal website, the Federal Depository Library Program, was defaced with pro-Iran messaging and an image of a bloodied President Trump, claimed by a group calling itself Iran Silk Hat, while CISA and the FBI renewed warnings about possible Iranian attacks on critical infrastructure. This retrospective maps the verified incidents of that week, separates hype from evidence, and explains why agencies treated the moment as a genuine escalation trigger despite limited actual damage.

Continue ReadingAfter Soleimani: The January 2020 US-Iran Cyber Alert Wave

Travelex Ransomware 2020: When Sodinokibi Crippled a Currency Giant

On 31 December 2019, foreign exchange giant Travelex took its UK and international websites and mobile apps offline following a cyberattack, an outage that also knocked out white-label travel money services at ASDA, Tesco and Sainsbury's overnight. When the story became public on 7 January 2020, the criminals behind Sodinokibi (REvil) ransomware were demanding 4.6 million pounds, claiming to have copied more than 5GB of customer data, and the company would spend weeks rebuilding systems by hand. This account reconstructs the verified timeline, the double-extortion playbook, and how the incident contributed to an August 2020 administration that cut more than a thousand UK jobs.

Continue ReadingTravelex Ransomware 2020: When Sodinokibi Crippled a Currency Giant
>