>

DP World Australia: When a Cyber Incident Stopped the Cranes

On 13 November 2023, DP World Australia disconnected its port systems from the internet to contain an intrusion — and container operations at Sydney, Melbourne, Brisbane and Fremantle stopped cold, stranding roughly 30,000 containers for three days. Operations resumed by 16 November, personnel data exposure was later confirmed, and no ransom payment was disclosed. The episode became Australia's reference case for cyber-driven supply-chain disruption and a model of disciplined containment, rapid restoration and honest capacity communication under SOI-Act scrutiny.

Continue ReadingDP World Australia: When a Cyber Incident Stopped the Cranes

ownCloud CVE-2023-49103: The CVSS 10.0 in the Docker Image

The graphapi app bundled in ownCloud's Docker deployment images exposed mail credentials, database passwords, and S3 keys to unauthenticated visitors — a mis-packaged dependency that became full infrastructure compromise. CISA KEV-listed it within ten days.

Continue ReadingownCloud CVE-2023-49103: The CVSS 10.0 in the Docker Image

ChatGPT’s November 2023 DDoS Outages, Explained

For much of 8 November 2023, ChatGPT and parts of OpenAI's API cycled in and out of service under a denial-of-service wave claimed by Anonymous Sudan, with smaller recurrences through the month. OpenAI confirmed the DDoS, rolled global WAF rules, and absorbed a false-positive tax on legitimate users. Nothing was breached — the story is availability risk wrapped around AI dependence. This post walks the campaign's anatomy, Microsoft's Storm-1359 telemetry link, and the business-continuity lessons for anyone running on AI vendors.

Continue ReadingChatGPT’s November 2023 DDoS Outages, Explained

LockBit, CitrixBleed, and the ICBC Treasury Hack

When LockBit hit ICBC's US broker-dealer on 9 November 2023, Treasury-market connectivity went dark and manual settlement took over for days. The entry path traced to CitrixBleed session tokens stolen before the October patch and never invalidated — exactly what CISA's Emergency Directive 23-08 had warned. LockBit claimed a roughly $9 million ransom demand, never verified. The post walks the token-replay kill chain, the disclosure-era aftermath, and the defensive lesson that remediation includes revocation.

Continue ReadingLockBit, CitrixBleed, and the ICBC Treasury Hack
>