WhatsApp’s 2022 Ring-Phase RCE: Code Execution Before You Answer
CVE-2022-36934 gave WhatsApp a CVSS 9.8 integer-overflow RCE that could execute during the video-call ring — before the victim answered. Zero interaction.
CVE-2022-36934 gave WhatsApp a CVSS 9.8 integer-overflow RCE that could execute during the video-call ring — before the victim answered. Zero interaction.
A Lapsus$-linked teenager allegedly reached Rockstar's Slack via helpdesk social engineering and posted 90+ GTA VI dev clips. The collaboration suite was the vault.
Australia's second-largest telco exposed ~9.8M customer records via an API left unauthenticated in production. No zero-day, no phishing — just enumeration.
An 18-year-old bought a contractor's Uber password, bombarded them with MFA pushes until one was approved, then roamed to vSphere via hardcoded credentials.
August's 'contained' developer-account compromise returned in December as stolen vault backups. Inside the two-act breach.
A forums database with bcrypt hashes and salts hit a criminal forum. The real blast radius was everywhere else users reused passwords.
Slope's telemetry backend held plaintext seed phrases, and attackers harvested them. The chain saw only valid signatures — and that is the whole lesson.
Fake Okta pages, real-time MFA relay, and one crew harvesting 10,000 identities. Why Cloudflare walked away clean and Twilio didn't.
A routine upgrade left message proofs rubber-stamped. Hundreds of copycats drained the bridge in crypto's most chaotic heist.
A patched OAuth endpoint answered one question too honestly: which phone belongs to which handle. The dataset sold for $30k — the class lesson is still with us.
A criminal franchise paid up to $1M for flaws in its own malware, website, and Tor infrastructure — Silicon Valley tactics inside the ransomware economy.
Furnaces halted, footage released, workers warned. How a state-aligned group turned industrial sabotage into broadcast messaging.