>

23andMe Credential Stuffing: When Relatives Are the Payload

Reused passwords took over 14,000 23andMe accounts, then the DNA Relatives feature amplified the access into profile data for 6.9 million genetically-linked users. The October 2023 breach rewrote breach math: your exposure now includes every relative's password hygiene.

Continue Reading23andMe Credential Stuffing: When Relatives Are the Payload

Okta Support Breach 2023: Session Tokens Beat MFA Again

Attackers compromised an Okta support engineer's personal device, stole the session cookies inside it, and used Okta's own support console against a customer base estimated at five percent of tenants. BeyondTrust, 1Password, and Cloudflare each detected the downstream activity independently — before the full scope was confirmed.

Continue ReadingOkta Support Breach 2023: Session Tokens Beat MFA Again

F5 BIG-IP Request Smuggling 2023: The 9.8 Desync

CVE-2023-46747 let unauthenticated attackers smuggle requests through BIG-IP TMM into the iControl REST management plane — a framing bug that became full device compromise. Exploitation followed the October patch within days, and CISA put it on the KEV catalog before month end.

Continue ReadingF5 BIG-IP Request Smuggling 2023: The 9.8 Desync

CitrixBleed CVE-2023-4966: Session Tokens Straight From Memory

CVE-2023-4966 let attackers read valid session tokens out of NetScaler memory and inherit authenticated sessions wholesale — MFA already passed. CISA's Emergency Directive 23-08 forced hunts and rebuilds as LockBit monetized the access.

Continue ReadingCitrixBleed CVE-2023-4966: Session Tokens Straight From Memory
>