WD My Book Live Mass Wipe: The EOL IoT Disaster
Tens of thousands of abandoned Western Digital NAS drives got factory-reset by strangers through a decade-old unpatched flaw. The definitive end-of-life IoT case study.
Tens of thousands of abandoned Western Digital NAS drives got factory-reset by strangers through a decade-old unpatched flaw. The definitive end-of-life IoT case study.
A leaked PoC, a patch that didn't patch, and weeks of registry-hardening confusion — how CVE-2021-34527 turned Windows Print Spooler into a domain-takeover primitive.
No attack, no breach — a single customer config met a dormant software bug and took Reddit, the Guardian, and roughly a tenth of the internet offline for an hour. The concentration-risk wake-up call.
780 GB of Frostbite engine and FIFA code left EA through a purchased Slack cookie and one help-desk MFA reset. The breach that proved sessions, not passwords, are the modern front door.
REvil halted the world's largest meat processor over a holiday weekend; JBS restored from backups — and still paid $11M for leak suppression and restart insurance. The economics of ransom beyond decryption.
EO 14028 turned zero trust from slide-ware into federal procurement doctrine — MFA, SBOMs, NIST 800-207, the Cyber Safety Review Board — and reset vendor incentives industry-wide.
AirTags made competent covert tracking cost $29 and zero skill. From pre launch warnings to prosecutions and the Apple-Google alert spec, the full history of a safety-by-design failure — and the platform fixes that finally landed.
DarkSide entered through a no-MFA legacy VPN password, exfiltrated 100 GB, and encrypted Colonial's IT — prompting a precautionary shutdown of 45% of East Coast fuel supply. Anatomy of the most policy-consequential ransomware ever.
ATT turned iOS advertising identifiers opt-in overnight, denial rates hit 80%+, and Meta booked a $10B impact. How one consent dialog restructured an ad economy — and pushed tracking into fingerprinting's arms.
Pre-auth Pulse Secure exploits handed APT crews and ransomware affiliates appliance-level control of the VPNs that carried pandemic remote work. How credential capture and patch-surviving persistence rewrote edge-appliance incident response.
A 2019 contact-import scrape of 533M users hit every phone number to profile, free-dumped in 2021 and still fueling vishing and SIM-swaps today. Why data age barely dents attacker value.
A tampered Codecov Bash Uploader quietly shipped CI environment variables — cloud keys, tokens, signing material — to attackers for two months. The curl-pipe-bash trust model dissected, and how build supply-chain security was rewritten after.