The 3CX Supply-Chain Attack: When Signed Updates Turn
3CX's signed desktop app shipped a trojan after its build pipeline fell to an upstream vendor compromise — the first documented double supply-chain attack.
3CX's signed desktop app shipped a trojan after its build pipeline fell to an upstream vendor compromise — the first documented double supply-chain attack.
SVB's March 2023 run froze payroll for half of venture-backed tech and minted a fraud wave targeting displaced customers. Treasury continuity lessons.
A redis-py cancellation bug plus a disabled key-prefix let some ChatGPT users see strangers' chat titles and billing data. Multi-tenant cache lessons.
Researchers pulled Bing Chat's hidden rules with polite overrides, revealing the codename Sydney and confidential guidelines. Prompt-injection's big bang.