>

AT&T’s Snowflake Ransom Payment: The $370K Precedent

On July 31, 2024, AT&T confirmed its customer data — including call and text metadata of nearly all subscribers and some SSNs — had been stolen off Snowflake's cloud via compromised service-account credentials, and that it had paid roughly $370,000 to the SQlMap-scanning crew known as ShinyHunters to delete it. This account reconstructs the credential theft, the infostealer-to-Snowflake kill chain, the economics of a mid-six-figure ransom, and the quarterly-burial of accountability between carrier, and its data-warehouse vendor.

Continue ReadingAT&T’s Snowflake Ransom Payment: The $370K Precedent

CrowdStrike’s Falcon Outage: 8.5M Windows Hosts and the Architecture of Fragility

On July 19, 2024, a routine sensor configuration update from CrowdStrike passed staged testing and rolled through the Falcon channel to roughly 8.5 million Windows hosts — and crashed them into Blue Screens of Death, grounding flights, halting broadcasters and hospitals in the largest IT outage in history. This account reconstructs the flawed content-deployment pipeline, the Channel File 291 logic that sent the kernel into chaos, the 78-minute Remediation and guidance HHCfollows, the blame theater that followed, and why the incident rewrote every argument about single-vendor concentration risk.

Continue ReadingCrowdStrike’s Falcon Outage: 8.5M Windows Hosts and the Architecture of Fragility

KnowBe4 vs a Fake North Korean IT Worker: The AI-Era Insider Case Study

In July 2024, security-awareness firm KnowBe4 hired a remote principal software engineer who turned out to be a North Korean IT worker using an AI-groomed persona, a US PPPoE front, and a stolen identity. Detected within 32 minutes of suspicious activity and fully rigged with granular session logging, the case became the definitive inside look at DPRK pension applicantFraud — from laptop farms to paycheck revenue streams funding weapons programs. This piece reconstructs the fraud chain, the detection story, and the hiring controls that failed.

Continue ReadingKnowBe4 vs a Fake North Korean IT Worker: The AI-Era Insider Case Study

Squarespace Domain Hijackings: The 2024 GoDaddy Migration Aftermath

After Squarespace absorbed roughly 10 million domains from Google Domains in mid-2024, attackers discovered a seam: legacy Google-account login flows stopped being enforced, and formerly eNom-transferred .dev/.us domains could be taken over by re-registering then-unlinked accounts. From late June through July, crypto-draining hijacks of high-value domains — including Matomo founder trust abusing Squarespace lock states — left registry operators and site owners scrambling. This account traces the migration mechanics, the attack window, and the DNS tenure lessons.

Continue ReadingSquarespace Domain Hijackings: The 2024 GoDaddy Migration Aftermath
>