>

Cisco BroadWorks CVE-2023-20237: The SSO Bypass Scare

In September 2023 Cisco rushed out patches for CVE-2023-20237, a critical authentication bypass in BroadWorks' single-sign-on flows that could let attackers authenticate as any user. With evidence of active scanning, carrier admins ran an emergency patch marathon.

Continue ReadingCisco BroadWorks CVE-2023-20237: The SSO Bypass Scare

MGM, Caesars, and Scattered Spider: The Vishing Fall of 2023

In September 2023 Scattered Spider vished the MGM helpdesk, pivoted through Okta to ESXi, and detonated ALPHV ransomware — a $100M quarter for MGM while Caesars paid up. The reference incident for helpdesk verification, MFA fatigue, and pay-vs-rebuild economics.

Continue ReadingMGM, Caesars, and Scattered Spider: The Vishing Fall of 2023

LAPSUS$ Convictions: Teenagers, Helpdesks, and the GTA VI Leak

A London jury convicted the teenage LAPSUS$ hackers whose SIM swaps, MFA-fatigue pushes, and helpdesk manipulation breached Nvidia, Microsoft, Okta, Uber, and Rockstar — closing the criminal case that proved identity is the real perimeter.

Continue ReadingLAPSUS$ Convictions: Teenagers, Helpdesks, and the GTA VI Leak

Storm-0558 Forged-Token Breach: The Stolen Key That Read Government Email

China-linked Storm-0558 forged Azure AD tokens with a stolen Microsoft consumer signing key and read email at ~25 organizations including the State and Commerce departments — exposing vendor key hygiene, token scope validation, and log-tiering as board-level security questions.

Continue ReadingStorm-0558 Forged-Token Breach: The Stolen Key That Read Government Email
>