>

Apple’s iOS 17.2 Bluetooth Fixes vs the Flipper Zero Craze

December 2023's patch wave closed the chapter on a strange season: cheap programmable gadgets spraying Bluetooth frames in public, iPhones crashing in viral videos, and Apple shipping denial-of-service fixes in the iOS 17.2 family. This piece explains the crash-pair CVEs, why Bluetooth's design makes every phone an always-on parser for stranger traffic, how the December 20 advisory window anchored the fixes, and why proximity protocols remain a permanent hardening frontier for every device maker.

Continue ReadingApple’s iOS 17.2 Bluetooth Fixes vs the Flipper Zero Craze

SMTP Smuggling: Spoofing Email With Authenticated Mail

December 2023 brought one of email's most elegant attacks: SMTP smuggling, a parser-level desync that tricks receiving servers into writing attacker-authored messages that pass SPF and DMARC because the victim's own infrastructure vouches for them. This deep dive covers the technique mechanics (end-of-data ambiguity, the second hidden MAIL FROM conversation), the December 19 disclosure and DHL demonstration, the two anchoring CVEs, which product families patched, and the durable lessons for mail admins running anything that speaks SMTP.

Continue ReadingSMTP Smuggling: Spoofing Email With Authenticated Mail

Mr. Cooper Mortgage Breach: The Week Payments Stopped

When one of America's largest mortgage servicers went dark for a week, the harm went far beyond stolen data. The Mr. Cooper incident — detected October 24, disclosed October 31, 2023 — halted payments, escrow, and payoffs for millions of borrowers, and later filings put the notification count near 14.7 million people with Social Security numbers and bank account details in the mix. This account covers the stolen-credential entry, the outage that regulators treated as the real injury, the mortgage-sector dependencies that amplified it, and the durable lessons for any payment-critical firm.

Continue ReadingMr. Cooper Mortgage Breach: The Week Payments Stopped

BGP Hijacking’s 2023 Resurgence, and What RPKI Fixed

All through 2023, route leaks and suspected BGP hijacks kept redirecting chunks of internet traffic — events touching Rostelecom-linked infrastructure, financial services, and a persistent streak of cryptocurrency-targeting interception paths. None matched the famed mass redirections of prior years, but the pattern of brief, deniable, hard-to-attribute incidents kept routing security in the research headlines. This year-end review explains how BGP trust fails, walks the 2023 incident ledger with appropriately hedged attribution, and covers the defensive state of the art: RPKI signing crossing majority coverage, MANRS norms, and external route monitoring.

Continue ReadingBGP Hijacking’s 2023 Resurgence, and What RPKI Fixed
>