>

SolarWinds Web Help Desk RCE: The Name That Hurts Again

On August 21-22, 2024, SolarWinds shipped 12.8.3 HF1 for Web Help Desk and disclosed CVE-2024-28986 — an unauthenticated Java deserialization flaw rated CVSS 9.8 that delivers pre-auth remote code execution on internet-facing instances. Within days PoC code circulated in exploitation attempts, and on August 26 CISA added it to the Known Exploited Vulnerabilities catalog, making patching mandatory across federal networks. This account covers the bug mechanics, the four-day disclosure-to-KEV sprint, and the uncomfortable optics of a SolarWinds product back in emergency-cycle headlines.

Continue ReadingSolarWinds Web Help Desk RCE: The Name That Hurts Again

The Telegram Arrest and the Encryption Debate of 2024

On August 24, 2024, French authorities arrested Telegram founder Pavel Durov at Le Bourget airport, and two days later charged him with complicity in organized-crime offenses enabled by his platform's refusal to cooperate with legal process — the first time a major encrypted-service executive faced criminal liability for governance choices. Released under judicial supervision within days, Durov's case forced every platform lawyer to reprice jurisdictional arbitrage, moderation staffing, and the meaning of cooperation. This account lays out the charges, the encryption-policy fault lines, and the compliance playbook that followed.

Continue ReadingThe Telegram Arrest and the Encryption Debate of 2024

Windows Downdate: Downgrade Attacks Against the OS Itself

At DEF CON 32 in August 2024, SafeBreach's Alon Leviev unveiled Downdate — a technique that abuses the Windows Modules Installer, TrustedInstaller privileges,and deliberately-eased vbsm manifest permission to silently roll back fully-patched Windows binaries to vulnerable prior versions, re-opening fixed BitLocker bypasses and Hyper-V escapes on current builds. This account explains the downgrade mechanics, the CVE-2024-21430 fix timeline, and why the research redefined patch currency as a security property worth defending.

Continue ReadingWindows Downdate: Downgrade Attacks Against the OS Itself

National Public Data: 2.9B SSN Records for the Price of a Breach

In August 2024, national background-check broker National Public Data confirmed a breach that leaked roughly 2.9 billion rows of personal records — names, addresses, relatives, SSNs — covering plausibly every US adult and parts of the UK and Canada, after a criminal actor first offered the data for sale in April and a third party then dumped 277GB free. This account traces the broker supply chain that assembled the dossier, the class-action lawsuit that forced acknowledgment, and the post-SSN security posture every organization now needs.

Continue ReadingNational Public Data: 2.9B SSN Records for the Price of a Breach
>