>

Colonial Pipeline Ransomware: One Password, 17 Emergency States

DarkSide entered through a no-MFA legacy VPN password, exfiltrated 100 GB, and encrypted Colonial's IT — prompting a precautionary shutdown of 45% of East Coast fuel supply. Anatomy of the most policy-consequential ransomware ever.

Continue ReadingColonial Pipeline Ransomware: One Password, 17 Emergency States

App Tracking Transparency: Apple’s Consent Earthquake, Five Years On

ATT turned iOS advertising identifiers opt-in overnight, denial rates hit 80%+, and Meta booked a $10B impact. How one consent dialog restructured an ad economy — and pushed tracking into fingerprinting's arms.

Continue ReadingApp Tracking Transparency: Apple’s Consent Earthquake, Five Years On

Pulse Secure VPN Zero-Days: When Remote Access Became the Front Door

Pre-auth Pulse Secure exploits handed APT crews and ransomware affiliates appliance-level control of the VPNs that carried pandemic remote work. How credential capture and patch-surviving persistence rewrote edge-appliance incident response.

Continue ReadingPulse Secure VPN Zero-Days: When Remote Access Became the Front Door

Codecov Breach: The CI Script That Leaked Build Secrets for Months

A tampered Codecov Bash Uploader quietly shipped CI environment variables — cloud keys, tokens, signing material — to attackers for two months. The curl-pipe-bash trust model dissected, and how build supply-chain security was rewritten after.

Continue ReadingCodecov Breach: The CI Script That Leaked Build Secrets for Months
>