>

Ivanti Endpoint Manager RCE: Two Bugs, One Dangerous Chain

On October 16, 2024, Ivanti disclosed two vulnerabilities in Endpoint Manager (EPM) chained for pre-auth remote code execution: CVE-2024-29224, an unauthenticated SSRF rated 9.6, and CVE-2024-29226, a path traversal in a downstream service. The week's disclosure calendar placed it days after FortiManager's FortiJump and amid a year of Ivanti security crises — from January's Connect Secure zero-days to September's Cloud Service Appliance flaw. This account explains the chain mechanics, why consortium defenders pushed urgent patching, and the management-plane pattern of 2024.

Continue ReadingIvanti Endpoint Manager RCE: Two Bugs, One Dangerous Chain

FortiManager Zero-Day (FortiJump): The Management-Plane Breach CISA Escalated

On October 23, 2024, Fortinet confirmed CVE-2024-47575 — a CVSS 9.8 missing-authentication flaw in the FortiManager FGFM protocol that China-nexus actor UNC5850 had exploited since summer to jump from exposed managers into fleets of managed FortiGates with a custom DeepMove implant. CISA KEV-listed it within days, forcing two-week patch deadlines across federal and enterprise fleets. This account reconstructs the protocol bug, the DeepMove persistence, the fleet-jump blast radius, and the management-plane hardening it made mandatory.

Continue ReadingFortiManager Zero-Day (FortiJump): The Management-Plane Breach CISA Escalated

Marriott’s FTC Settlement: 20 Years of Audits for Starwood’s Ghosts

On October 9, 2024, the FTC announced a pair of consent orders — Marriott and its Starwood subsidiary — resolving claims that skimped security contributed to the 2014-2018 Starwood intrusions and a 2018 breach affecting over 131 million consumers from which attackers extracted 5.25 million unencrypted passport numbers. The order imposes 20 years of independent assessments and a claims program offering $150 cash orotomy spending on security — close kin to the UK ICO's £18.4M fine and the states' $52M settlement. This account traces the 2014→2018 intrusion, the regulatory pile-on, and what a two-decade oversight tail teaches about inherited security debt.

Continue ReadingMarriott’s FTC Settlement: 20 Years of Audits for Starwood’s Ghosts

Internet Archive Breach and DDoS: 31M Accounts, One Pop-Up

On October 9, 2024, visitors to the Internet Archive's Wayback Machine were greeted by an injected JavaScript pop-up announcing the compromise of 31,081,179 user accounts — the HIBP-confirmed count of the organization's authentication database, loaned from a September exposure of its Zendesk support portal. A concurrent DDoS attributed to SN_BlackMeta compounded the disruption; days later, archived XSS attempts confirmed the org'sJavaScript security debt. This account traces the initial access, the pop-up's evidence chain, and the funding-and-fragility story of a library built on hope.

Continue ReadingInternet Archive Breach and DDoS: 31M Accounts, One Pop-Up

Cisco SSM On-Prem Flaws: CVSS 10.0 and a CLI Zero-Day in One Week

In early October 2024, Cisco's disclosure cadence stacked two unrelated but equally urgent problems: CVE-2024-20419, a CVSS 10.0 unauthenticated password-change flaw in Smart Software Manager On-Prem that let anyone with network access reset the admin API account, and CVE-2024-20399, a CLI command-injection bug in NX-OS already being exploited in the wild per the CISA KEV catalog. This account reconstructs both flaws' mechanics, the patch timelines, and what this pairing says about authentication surface area in management tooling.

Continue ReadingCisco SSM On-Prem Flaws: CVSS 10.0 and a CLI Zero-Day in One Week
>