>

CVE-2024-10924: Really Simple Security’s 2FA Betrayal

On November 6, 2024, Wordfence researcher István Márton disclosed CVE-2024-10924 — a CVSS 9.8 authentication bypass in Really Simple Security, the plugin securing four million WordPress sites, whose two-factor onboarding endpoint failed to validate the requesting user, granting attackers admin sessions on sites with incomplete 2FA enrollment. Patched same-day in 9.1.2, NVD-published November 14, the flaw became 2024's definitive case study in security-plugin risk. This account walks the vulnerable code path, the four-million-site patch sprint, and why the ecosystem's auth surface extends far past WordPress core.

Continue ReadingCVE-2024-10924: Really Simple Security’s 2FA Betrayal

Arup’s HK$200M Deepfake Call: The CFO Fraud Manual Rewritten

In February 2024, a finance employee at Arup's Hong Kong office paid out roughly HK$200 million (US$25.6M) across fifteen transfers after a video conference in which every other participant — including the UK-based CFO — was a deepfake, built from public footage and commodity cloning tools. Police detailed the case on February 4, and by year-end it stood as the largest documented deepfake-enabled financial fraud: phishing to set the pretext, a synthetic multi-person call to seal it. This account reconstructs the con, the tooling economics, and the verification-protocol redesign it forced.

Continue ReadingArup’s HK$200M Deepfake Call: The CFO Fraud Manual Rewritten

Magecart’s 2024 Resurgence: Skimming in the Polyfill.io Aftermath

Through 2024, digital skimming returned to threat reports' front pages: Magecart-style attacks compromised hundreds of storefronts via compromised third-party JavaScript, supply-chain infections like polyfill.io's June domain takeover injected malicious scripts into vast numbers of pages, and PCI DSS 4.0's script-integrity requirements (6.4.3 and 11.6.2) approached their March 2025 enforcement deadline. This survey digests the modern skimming kill chain — injection, exfiltration, and evasion — the major 2024 campaigns, and the compliance clock turning client-side risk into boardroom math.

Continue ReadingMagecart’s 2024 Resurgence: Skimming in the Polyfill.io Aftermath

F5 BIG-IP Next Central Manager: The Unauthenticated Takeover Bugs

On November 6, 2024, F5 disclosed a pair of critical bugs in BIG-IP Next Central Manager shipped in its SPK fabric: CVE-2024-23327, an unauthenticated privilege-escalation path reachable via REST API, and CVE-2024-23328, a missing-authentication flaw letting attackers create arbitrary administrator accounts. Together they enable full takeover of a management node that itself commands a fleet of application delivery hardware. This account walks both paths, the same-day patches, and the uncomfortable lineage going back to CVE-2022-1388's iControl REST flaw.

Continue ReadingF5 BIG-IP Next Central Manager: The Unauthenticated Takeover Bugs

Snowflake-Related Arrests: UNC5537’s Kitchener Pinch

On October 30, 2024, Canadian authorities arrested a 26-year-old Kitchener, Ontario man on a US warrant connecting him to the Snowflake-account intrusions tracked by Mandiant as UNC5537 — the crew behind the Ticketmaster, Santander, and AT&T disclosures that dominated 2024's data-theft calendar. The arrest, first reported in early November by Bloomberg identifying the suspect as Connor Riley Moucka, illuminated the infostealer-credential-to-cloud kill chain and the market for stolen data. This account reconstructs the campaign, the arrest, and the MFA lessons that outlast it.

Continue ReadingSnowflake-Related Arrests: UNC5537’s Kitchener Pinch
>