MOVEit Transfer Zero-Day: Cl0p’s Memorial Day Heist
CVE-2023-34362 in MOVEit Transfer let Cl0p deploy the LEMURLOOT web shell at scale over Memorial Day weekend — pure data extortion, no encryption, hundreds of downstream victims.
CVE-2023-34362 in MOVEit Transfer let Cl0p deploy the LEMURLOOT web shell at scale over Memorial Day weekend — pure data extortion, no encryption, hundreds of downstream victims.
Ireland's DPC fined Meta €1.2B over EU-US transfers that Schrems II had already doomed — the largest GDPR fine ever, ordering suspension and deletion. Transfer-governance lessons for security teams.
A server-side fault in ASUS's firmware-update mechanism crashed routers worldwide, requiring manual recovery — a global outage delivered through the trusted update path, no attacker required.
A 2023 PoC scraped the KeePass master password from memory via a rogue DLL; the maintainer called it working as designed. Both were right — and the endpoint-is-the-perimeter lesson stuck.