>

HAFNIUM and Exchange Zero-Days: The 30,000-Server Compromise

Four zero-days in on-premises Microsoft Exchange let HAFNIUM and ten follow-on crews own mail servers at tens of thousands of organisations. The anatomy of the SSRF-to-web-shell chain, the PATCH NOW scramble, and why patching was not remediation.

Continue ReadingHAFNIUM and Exchange Zero-Days: The 30,000-Server Compromise

CD Projekt Red Ransomware: The Source-Code Auction That Failed

HelloKitty ransomware encrypted CDPR's network and stole Cyberpunk 2077 and Witcher 3 source code — then auctioned it on a crime forum after the studio refused to pay. The incident file on IP extortion, auction economics, and the no-ransom playbook.

Continue ReadingCD Projekt Red Ransomware: The Source-Code Auction That Failed

Dependency Confusion: How a Researcher Hacked Apple and Microsoft

No exploits, no stolen credentials — Alex Birsan's February 2021 research got code executed inside 35+ major companies by registering their internal package names on public registries and letting version arithmetic do the rest. The incident file on the cheapest supply-chain attack ever demonstrated.

Continue ReadingDependency Confusion: How a Researcher Hacked Apple and Microsoft

Chrome V8 Zero-Day CVE-2021-21148: Anatomy of a Drive-By

Google's February 2021 emergency Chrome patch opened a record zero-day year. This incident file breaks down how the V8 heap overflow worked, how it chained with a sandbox escape, why watering-hole delivery leaves no trace, and what fleet-level browser defenses it forced.

Continue ReadingChrome V8 Zero-Day CVE-2021-21148: Anatomy of a Drive-By

Oldsmar Water Plant Hack: The Five-Minute SCADA Wakeup Call

A remote intruder raised a Florida treatment plant's lye setpoint from 100 to 11,100 ppm and an operator watching the screen reverted it in minutes. The incident file on shared passwords, exposed TeamViewer, and why OT security failed at a municipal water utility.

Continue ReadingOldsmar Water Plant Hack: The Five-Minute SCADA Wakeup Call

Emotet Takedown: How Police Dismantled the World’s Most Dangerous Malware

The incident file on Operation Ladybird: how eight countries dismantled Emotet's 700-server botnet from inside its own update mechanism, why the loader-as-a-service model made Emotet the on-ramp for Ryuk and Conti ransomware, how the brand was rebuilt from TrickBot within ten months, and what the takedown teaches about the ceiling of law-enforcement disruption.

Continue ReadingEmotet Takedown: How Police Dismantled the World’s Most Dangerous Malware

SonicWall SMA Zero-Day: Inside the January 2021 SSL-VPN Campaign

Days after SUNBURST, researchers caught attackers exploiting a 9.8-severity SQL injection in SonicWall SMA 100 appliances — including against SonicWall's own network. This incident file covers how unauthenticated credential extraction turned edge appliances into ransomware on-ramps.

Continue ReadingSonicWall SMA Zero-Day: Inside the January 2021 SSL-VPN Campaign

SolarWinds SUNBURST: Inside the Supply-Chain Attack That Rewrote Security

The full incident file on the SolarWinds SUNBURST supply-chain attack: how SVR-linked actors compromised the Orion build pipeline, trojanized signed updates reaching 18,000 customers, hand-picked under 100 targets including nine US federal agencies, and forged SAML tokens to persist. Includes the technical anatomy, timeline, impact numbers, and the build-pipeline hardening lessons that still define defender programs in 2026.

Continue ReadingSolarWinds SUNBURST: Inside the Supply-Chain Attack That Rewrote Security
>