Western Digital’s My Cloud Outage: Vendor Risk for NAS
WD's 2023 intrusion took My Cloud services offline mid-extortion claims, locking users out of their own files. Cloud-tethered storage lessons.
WD's 2023 intrusion took My Cloud services offline mid-extortion claims, locking users out of their own files. Cloud-tethered storage lessons.
3CX's signed desktop app shipped a trojan after its build pipeline fell to an upstream vendor compromise — the first documented double supply-chain attack.
SVB's March 2023 run froze payroll for half of venture-backed tech and minted a fraud wave targeting displaced customers. Treasury continuity lessons.
A redis-py cancellation bug plus a disabled key-prefix let some ChatGPT users see strangers' chat titles and billing data. Multi-tenant cache lessons.
Researchers pulled Bing Chat's hidden rules with polite overrides, revealing the codename Sydney and confidential guidelines. Prompt-injection's big bang.
Phishers compromised a SendGrid supplier account and sent MetaMask-themed mail through Namecheap's legitimate pipeline — SPF, DKIM, and DMARC all passed.
A cloned intranet page harvested an employee's password and MFA code, opening hours of internal access. Phishing-resistant MFA and self-report lessons.
GoDaddy's 2023 filing admitted intermittent intruder access since 2020, malware in cPanel servers, and email interception affecting ~6.95M customers.
ESXiArgs hit thousands of unpatched VMware ESXi hosts via old OpenSLP bugs in February 2023. Hypervisor ransomware and recovery-script lessons.
Git's January 2023 advisory flagged plaintext credential stores and verbose logs echoing 2FA tokens. Developer tooling is production security surface.
A single compromised API credential let an actor scrape ~37 million T-Mobile accounts over six weeks. Machine-identity governance lessons from a repeat offender.
LockBit encrypted Royal Mail's international sorting operations in January 2023 and demanded $80M. Royal Mail paid nothing and kept the letters moving.