>

Sisense Breach: CI Credentials, AWS Keys and a CISA Advisory

On April 24, 2024, CISA and the FBI advised every Sisense customer to rotate credentials after attackers compromised the BI vendor's development environment — and by week's end, Sisense-issued AWS keys were circulating publicly. This piece reconstructs the five-day arc from detection to contained, explains why business-intelligence platforms are credential funnels that turn vendor CI/CD breaches into customer incidents, and extracts the third-party-risk doctrine the episode left behind for every embedded-analytics supply chain.

Continue ReadingSisense Breach: CI Credentials, AWS Keys and a CISA Advisory

CrushFTP VFS Sandbox Escape: Zero-Trust Patch Confusion in File Transfer

On April 19-20, 2024, CrushFTP shipped emergency fixes for CVE-2024-4040 — an unauthenticated escape from the virtual file system sandbox that exposed arbitrary host files, including the credential-stuffed configuration that anchors enterprise partner integrations. Exploitation followed within days, CISA listed it April 30, and a chaotic trail of interim builds left customers arguing about version numbers mid-fire. This account covers the traversal-to-escape chain, the mainserv credential hunt, and the hard lessons of small-vendor emergency patching.

Continue ReadingCrushFTP VFS Sandbox Escape: Zero-Trust Patch Confusion in File Transfer

PuTTY ECDSA Nonce Bias: How 71 Signatures Exposed Your SSH Key

PuTTY's April 2024 advisory for CVE-2024-31497 read like a physics problem: the terminal's ECDSA implementation biased nonces on NIST P-521, so roughly 71 captured SSH signatures suffice for a lattice attack that recovers the private key. This piece explains the Hidden Number Problem math, why archived PCAP and DLP session capture retroactively weaponized years of traffic, the 0.81 deterministic-nonce fix, and the brutal rotation drill that made every P-521 key used through Pageant presumptively burned.

Continue ReadingPuTTY ECDSA Nonce Bias: How 71 Signatures Exposed Your SSH Key

PAN-OS GlobalProtect Command Injection: April 2024’s Zero-Day Race (CVE-2024-3400)

On April 12, 2024, WatchTowr disclosed CVE-2024-3400 — a CVSS 10.0 pre-auth command injection in PAN-OS GlobalProtect that state-sponsored actors had exploited since late March by chaining a cookie-controlled file write into Tcl execution as root. This account walks the two-flaw exploit chain, the scramble after the 10.2.9-h1 hotfix, CISA's KEV clock, config-hidden persistence that survived reboots, the mitigation-versus-remediation confusion, and why 2024 made appliances patch with server-grade urgency.

Continue ReadingPAN-OS GlobalProtect Command Injection: April 2024’s Zero-Day Race (CVE-2024-3400)

AT&T 73M Leak: The 2019 Dataset That Resurfaced Free

March 2024's 73-million-record AT&T leak was an old wound reopened: a 2019-era vendor-workspace dataset, shopped unsuccessfully in 2021, finally dumped free on a hacking forum with SSNs and account details intact. This account disentangles it from the concurrent Snowflake campaign, explains why free publication maximizes criminal utility, maps the 7.6 million passcode resets, and follows the extortion thread that later surfaced in DOJ filings.

Continue ReadingAT&T 73M Leak: The 2019 Dataset That Resurfaced Free
>