>

CD Projekt Red Ransomware: The Source-Code Auction That Failed

HelloKitty ransomware encrypted CDPR's network and stole Cyberpunk 2077 and Witcher 3 source code — then auctioned it on a crime forum after the studio refused to pay. The incident file on IP extortion, auction economics, and the no-ransom playbook.

Continue ReadingCD Projekt Red Ransomware: The Source-Code Auction That Failed

Dependency Confusion: How a Researcher Hacked Apple and Microsoft

No exploits, no stolen credentials — Alex Birsan's February 2021 research got code executed inside 35+ major companies by registering their internal package names on public registries and letting version arithmetic do the rest. The incident file on the cheapest supply-chain attack ever demonstrated.

Continue ReadingDependency Confusion: How a Researcher Hacked Apple and Microsoft

Chrome V8 Zero-Day CVE-2021-21148: Anatomy of a Drive-By

Google's February 2021 emergency Chrome patch opened a record zero-day year. This incident file breaks down how the V8 heap overflow worked, how it chained with a sandbox escape, why watering-hole delivery leaves no trace, and what fleet-level browser defenses it forced.

Continue ReadingChrome V8 Zero-Day CVE-2021-21148: Anatomy of a Drive-By

Oldsmar Water Plant Hack: The Five-Minute SCADA Wakeup Call

A remote intruder raised a Florida treatment plant's lye setpoint from 100 to 11,100 ppm and an operator watching the screen reverted it in minutes. The incident file on shared passwords, exposed TeamViewer, and why OT security failed at a municipal water utility.

Continue ReadingOldsmar Water Plant Hack: The Five-Minute SCADA Wakeup Call
>