>

LockBit Takedown: Operation Cronos and Its Awkward Aftermath

February 2024's Operation Cronos seized LockBit's infrastructure across a dozen countries — and then the leaks showed how long the FBI had been inside. This account covers the covert access, the sting timing driven by UK hospital targeting, the servers and affiliate accounts taken down, the hurried rebrand to LockBit 4.1, the affiliate diaspora to RansomHub and Akira, and the awkward questions the takedown's trolling raised about reading crime statistics.

Continue ReadingLockBit Takedown: Operation Cronos and Its Awkward Aftermath

Change Healthcare ALPHV: The Ransomware That Broke US Healthcare

One ALPHV/BlackCat intrusion in February 2024 froze claims and pharmacy payments across US healthcare for weeks — the single most consequential ransomware attack of the year. This account covers the nine-day dwell time, the $22 million ransom payment and the exit-scam double-cross that brought RansomHub back for seconds, the eventual disclosure of hundreds of millions of records, and why one processor's central position converted a single encryptor into a national healthcare liquidity crisis.

Continue ReadingChange Healthcare ALPHV: The Ransomware That Broke US Healthcare

ConnectWise ScreenConnect Auth Bypass: An Instant RCE Wave

February 2024's CVE-2024-1709 let anyone add administrative accounts to self-hosted ScreenConnect servers — a setup-wizard path traversal that converted remote-support consoles into ransomware deployment platforms within 72 hours of disclosure. This account covers the twinned vulnerabilities, why MSP-hosted instances multiplied the blast radius across client fleets, the observed ransomware sequences, and the hard questions RMM vendors faced about unauthenticated wizard endpoints.

Continue ReadingConnectWise ScreenConnect Auth Bypass: An Instant RCE Wave

Wyze Camera Flaw: 13,000 Strangers Through One Caching Hole

Two February 2024 vulnerabilities let Wyze app users briefly see thumbnails and live feeds of strangers' cameras — a cache-key failure amplified by a three-year-old flaw resurfacing in redesigned hardware. This account covers the date-based cache-key bug, the 13,000 affected users, the nine-hour fleet update, and the uncomfortable questions about budget-camera security engineering when the same vendor has now repeated the vulnerability class.

Continue ReadingWyze Camera Flaw: 13,000 Strangers Through One Caching Hole

AnyDesk Breach: Production Compromise and a Certificate Sprint

Remote-access maker AnyDesk confirmed in February 2024 that attackers had compromised production systems using valid credentials traced to infostealer logs — forcing a certificate rotation, password resets, and a rushed 8.1.1 release whose code-signing was intact but whose credibility needed rebuilding. This piece covers the infostealer-to-supply-chain escalation path that rewired vendor-risk thinking, and why remote-admin tooling became a tier-one identity perimeter.

Continue ReadingAnyDesk Breach: Production Compromise and a Certificate Sprint
>