>

Kadrey v. Meta: Piracy Allegations and the Llama Paper Trail

In mid-December 2024, unsealed filings in Kadrey et al. v. Meta Platforms alleged the company torrented LibGen's pirated library while engineers warned it 'doesn't feel right' on corporate laptops, stripped copyright management information with purpose-built scripts, and used a dataset a memo called 'we know to be pirated' — with CEO approval over executive objections. The proposed DMCA and CDAFA claims reframe the AI-copyright fight around distribution and concealment rather than fair use alone. This account walks the exhibits, the legal architecture, and the compliance lessons for every AI data program.

Continue ReadingKadrey v. Meta: Piracy Allegations and the Llama Paper Trail

NIST’s PQC Standards: FIPS 203-205 and the Migration Clock

On August 13, 2024, NIST published the final versions of FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) — the first formal post-quantum cryptography standards, capping an eight-year open competition and starting the migration clock for RSA and elliptic-curve infrastructure. With harvest-now-decrypt-later collection already threatening long-lived secrets and federal migration timelines targeting the 2030s, enterprises face a decade-scale cryptographic inventory and replacement program. This guide walks the standards, the threat math, and the migration playbook from inventory to hybrid deployment.

Continue ReadingNIST’s PQC Standards: FIPS 203-205 and the Migration Clock

Tool Hijacking: The 2024 Papers That Predicted Agent Attacks

By November 2024, AI-agent security research had already documented the attack class that production incidents would later make infamous. InjecAgent (March 2024, ACL Findings) benchmarked 1,054 indirect-injection scenarios across 30 agents, finding ReAct-prompted GPT-4 attacked successfully roughly a quarter of the time. Breaking Agents (July 2024) demonstrated malfunction amplification through agentic loops. Together with 2023's foundational indirect-prompt-injection work, they mapped how tools, descriptions, and fetched content become command channels. This survey walks the papers, the hijack taxonomy, and the controls that predate the incidents.

Continue ReadingTool Hijacking: The 2024 Papers That Predicted Agent Attacks

CVE-2024-10924: Really Simple Security’s 2FA Betrayal

On November 6, 2024, Wordfence researcher István Márton disclosed CVE-2024-10924 — a CVSS 9.8 authentication bypass in Really Simple Security, the plugin securing four million WordPress sites, whose two-factor onboarding endpoint failed to validate the requesting user, granting attackers admin sessions on sites with incomplete 2FA enrollment. Patched same-day in 9.1.2, NVD-published November 14, the flaw became 2024's definitive case study in security-plugin risk. This account walks the vulnerable code path, the four-million-site patch sprint, and why the ecosystem's auth surface extends far past WordPress core.

Continue ReadingCVE-2024-10924: Really Simple Security’s 2FA Betrayal

Arup’s HK$200M Deepfake Call: The CFO Fraud Manual Rewritten

In February 2024, a finance employee at Arup's Hong Kong office paid out roughly HK$200 million (US$25.6M) across fifteen transfers after a video conference in which every other participant — including the UK-based CFO — was a deepfake, built from public footage and commodity cloning tools. Police detailed the case on February 4, and by year-end it stood as the largest documented deepfake-enabled financial fraud: phishing to set the pretext, a synthetic multi-person call to seal it. This account reconstructs the con, the tooling economics, and the verification-protocol redesign it forced.

Continue ReadingArup’s HK$200M Deepfake Call: The CFO Fraud Manual Rewritten

Magecart’s 2024 Resurgence: Skimming in the Polyfill.io Aftermath

Through 2024, digital skimming returned to threat reports' front pages: Magecart-style attacks compromised hundreds of storefronts via compromised third-party JavaScript, supply-chain infections like polyfill.io's June domain takeover injected malicious scripts into vast numbers of pages, and PCI DSS 4.0's script-integrity requirements (6.4.3 and 11.6.2) approached their March 2025 enforcement deadline. This survey digests the modern skimming kill chain — injection, exfiltration, and evasion — the major 2024 campaigns, and the compliance clock turning client-side risk into boardroom math.

Continue ReadingMagecart’s 2024 Resurgence: Skimming in the Polyfill.io Aftermath

F5 BIG-IP Next Central Manager: The Unauthenticated Takeover Bugs

On November 6, 2024, F5 disclosed a pair of critical bugs in BIG-IP Next Central Manager shipped in its SPK fabric: CVE-2024-23327, an unauthenticated privilege-escalation path reachable via REST API, and CVE-2024-23328, a missing-authentication flaw letting attackers create arbitrary administrator accounts. Together they enable full takeover of a management node that itself commands a fleet of application delivery hardware. This account walks both paths, the same-day patches, and the uncomfortable lineage going back to CVE-2022-1388's iControl REST flaw.

Continue ReadingF5 BIG-IP Next Central Manager: The Unauthenticated Takeover Bugs

Snowflake-Related Arrests: UNC5537’s Kitchener Pinch

On October 30, 2024, Canadian authorities arrested a 26-year-old Kitchener, Ontario man on a US warrant connecting him to the Snowflake-account intrusions tracked by Mandiant as UNC5537 — the crew behind the Ticketmaster, Santander, and AT&T disclosures that dominated 2024's data-theft calendar. The arrest, first reported in early November by Bloomberg identifying the suspect as Connor Riley Moucka, illuminated the infostealer-credential-to-cloud kill chain and the market for stolen data. This account reconstructs the campaign, the arrest, and the MFA lessons that outlast it.

Continue ReadingSnowflake-Related Arrests: UNC5537’s Kitchener Pinch

Ivanti Endpoint Manager RCE: Two Bugs, One Dangerous Chain

On October 16, 2024, Ivanti disclosed two vulnerabilities in Endpoint Manager (EPM) chained for pre-auth remote code execution: CVE-2024-29224, an unauthenticated SSRF rated 9.6, and CVE-2024-29226, a path traversal in a downstream service. The week's disclosure calendar placed it days after FortiManager's FortiJump and amid a year of Ivanti security crises — from January's Connect Secure zero-days to September's Cloud Service Appliance flaw. This account explains the chain mechanics, why consortium defenders pushed urgent patching, and the management-plane pattern of 2024.

Continue ReadingIvanti Endpoint Manager RCE: Two Bugs, One Dangerous Chain

FortiManager Zero-Day (FortiJump): CISA Escalation Explained

On October 23, 2024, Fortinet confirmed CVE-2024-47575 — a CVSS 9.8 missing-authentication flaw in the FortiManager FGFM protocol that China-nexus actor UNC5850 had exploited since summer to jump from exposed managers into fleets of managed FortiGates with a custom DeepMove implant. CISA KEV-listed it within days, forcing two-week patch deadlines across federal and enterprise fleets. This account reconstructs the protocol bug, the DeepMove persistence, the fleet-jump blast radius, and the management-plane hardening it made mandatory.

Continue ReadingFortiManager Zero-Day (FortiJump): CISA Escalation Explained

Marriott’s FTC Settlement: 20 Years of Audits for Starwood’s Ghosts

On October 9, 2024, the FTC announced a pair of consent orders — Marriott and its Starwood subsidiary — resolving claims that skimped security contributed to the 2014-2018 Starwood intrusions and a 2018 breach affecting over 131 million consumers from which attackers extracted 5.25 million unencrypted passport numbers. The order imposes 20 years of independent assessments and a claims program offering $150 cash orotomy spending on security — close kin to the UK ICO's £18.4M fine and the states' $52M settlement. This account traces the 2014→2018 intrusion, the regulatory pile-on, and what a two-decade oversight tail teaches about inherited security debt.

Continue ReadingMarriott’s FTC Settlement: 20 Years of Audits for Starwood’s Ghosts

Internet Archive Breach and DDoS: 31M Accounts, One Pop-Up

On October 9, 2024, visitors to the Internet Archive's Wayback Machine were greeted by an injected JavaScript pop-up announcing the compromise of 31,081,179 user accounts — the HIBP-confirmed count of the organization's authentication database, loaned from a September exposure of its Zendesk support portal. A concurrent DDoS attributed to SN_BlackMeta compounded the disruption; days later, archived XSS attempts confirmed the org'sJavaScript security debt. This account traces the initial access, the pop-up's evidence chain, and the funding-and-fragility story of a library built on hope.

Continue ReadingInternet Archive Breach and DDoS: 31M Accounts, One Pop-Up
>