26 Million Requests Per Second: Cloudflare’s Record DDoS
Five thousand cloud VMs, each pushing 5,000 rps of encrypted traffic at one small website. June 2022's record flood and the edge doctrine it sealed.
Five thousand cloud VMs, each pushing 5,000 rps of encrypted traffic at one small website. June 2022's record flood and the edge doctrine it sealed.
A 2-of-5 multisig guarding nine figures. Lazarus took the two keys it needed, and the bridge-custody era changed for good.
Sixteen days between disclosure and patch. Who exploited Follina in the gap, how fast state and commodity actors moved, and the doctrine it forged.
Exploited in the wild two days before the patch existed. How OGNL injection turned Confluence into June 2022's internet-scale fire drill — and the playbook it left behind.
A protocol handler, a remote template, a signed diagnostic tool — CVE-2022-30190 executed PowerShell from a Word file with macros fully disabled.
Rotating MAC addresses were supposed to make Bluetooth anonymous. May 2022's synthesis of research, stalker hardware, and detection tools proved they never did.
GitHub's OAuth tokens lived in Heroku's infrastructure. One compromised CI cache later, an ecosystem learned where vendor tokens really live.
No stolen keys, no exploit — just a death spiral in the mechanism itself. Why UST's fall is mandatory reading for DeFi threat modelling.
No key stolen, no bug exploited — an attacker borrowed a voting majority on Aave, passed his own proposal, and drained the vaults in one block.
Conti encrypted the treasury during tax season, declared war on the government, and forced the world's first ransomware state of emergency.
Attackers stole GitHub integration tokens from Heroku and Travis CI, pivoted into npm, and downloaded ~109,000 publishing credentials.
A JDK 9 property path reopened a 2010-era bug class in Spring's data binder — and gave every Tomcat admin a very bad 48 hours.