>

APT29 Inside TeamViewer: 2024’s Calmest, Most Instructive Breach

On June 28, 2024, TeamViewer disclosed that a state-sponsored actor — widely reported as Russia's APT29 — had breached its corporate IT network through a standard employee's credentials, and that the remote-access product itself, and every customer, stayed untouched. This account reconstructs the hours-to-containment timeline, explains why corporate/product segmentation carried the day, places the intrusion in Cozy Bear's patient espionage season, and draws the anti-SolarWinds comparison that made this 2024's most instructive breach.

Continue ReadingAPT29 Inside TeamViewer: 2024’s Calmest, Most Instructive Breach

Polyfill.io Hijack: 100,000+ Sites Inherited a Malicious Script

When Sansec disclosed in late June 2024 that the polyfill.io domain had been sold and its hosted script rewritten to inject mobile-only scam redirects, hundreds of thousands of embedded sites — WordPress themes among them — discovered they had inherited an implant, invisible to desktop QA by design. This account traces the Funnull acquisition chain, the conditional payload mechanics, Cloudflare's mirror intervention, the DNS-harassment retaliation, the 2025 arrests, and the inventory lesson every site owner still owes themselves.

Continue ReadingPolyfill.io Hijack: 100,000+ Sites Inherited a Malicious Script

Brain Cipher vs Indonesia’s Data Centers: A National Ransomware Reckoning

In June 2024, the Brain Cipher crew — running a LockBit 3.0 builder clone — encrypted Indonesia's National Data Center, disrupting 200+ government services from immigration to licensing, then released a decryptor with an apology-flavored admission that extortion failed, then hit again during recovery. This account covers the copycat-crew economics behind the operation, why one shared-tenant data center meant national outage, the second-encryption lesson about persistence, and the segmented-architecture rebuild Indonesia promised next.

Continue ReadingBrain Cipher vs Indonesia’s Data Centers: A National Ransomware Reckoning

CDK Global Ransomware: US Car Dealerships Run on Pen and Paper

On June 19, 2024, ransomware hit CDK Global's dealer management platform — the operational nervous system of ~15,000 North American dealerships — and a second strike during recovery extended the outage for weeks while finance desks, service bays and OEM ordering reverted to paper and fax. This account covers the June 19/22 double-hit timeline, the billion-dollar industry loss estimates, why DMS lock-in made fallback manual rather than competitive, and the concentration-risk docket the incident left for every regulator to cite.

Continue ReadingCDK Global Ransomware: US Car Dealerships Run on Pen and Paper

The Snowflake Extortion Campaign at Its Peak: 165+ Customers, One Credential Wave

On June 19, 2024, Mandiant's public advisory named UNC5537 as the crew behind the Snowflake extortion wave — 165+ victim organizations entered with infostealer credentials against MFA-less tenants, datasets extorted through listings and a dedicated leak market researchers dubbed Snow:Bay. This piece condenses the TTP catalogue, the backyard economics of stolen logs, the aftermarket that changed notification obligations forever, and the single control that would have prevented every confirmed intrusion.

Continue ReadingThe Snowflake Extortion Campaign at Its Peak: 165+ Customers, One Credential Wave

Snowflake-Ticketmaster: The Credential Wave That Broke the Cloud-Secure Myth

Live Nation's May 2024 SEC filing confirmed criminal access to roughly 560 million Ticketmaster customer records — taken not by exploiting Snowflake but by logging into it with infostealer-derived credentials on a tenant without MFA. This account explains the UNC5537 tradecraft that chained $20 stealer logs into Fortune-500 data lakes, why the 'no Snowflake breach' defense only half-worked, what the ~560M-record dataset contained, and the mandatory-MFA wave that reshaped SaaS identity through 2024.

Continue ReadingSnowflake-Ticketmaster: The Credential Wave That Broke the Cloud-Secure Myth

Windows Recall: The Privacy Architecture Debate Before a Single Line Shipped

Announced May 20, 2024 as a Copilot+ flagship, Windows Recall promised searchable memory of everything on screen — and researchers found the archive in a plaintext SQLite database any user-context malware could read, with a runtime API to match. This account covers Kevin Beaumont's teardown, the TotalRecall extraction tool, the threat-model fallacies in each Microsoft defense, the June climb-down to opt-in plus Windows Hello and encryption, and the rare process win of an architecture changed before deployment.

Continue ReadingWindows Recall: The Privacy Architecture Debate Before a Single Line Shipped

Google AI Overviews: Prompt Injection Hits the Homepage of the Internet

When Google rolled AI Overviews into US search in May 2024, satirical sources got quoted as fact at national scale — glue on pizza, rocks as vitamins — and security researchers reframed the comedy as indirect prompt injection: retrieved content steering the answer in Google's own voice. This piece tracks the launch-week failures, the overview-bait SEO economy that followed, the manual-removal treadmill, provenance-aware retrieval as the real fix, and why RAG systems inherit the trust profile of their worst-cited source.

Continue ReadingGoogle AI Overviews: Prompt Injection Hits the Homepage of the Internet

Sisense Breach: CI Credentials, AWS Keys and a CISA Advisory

On April 24, 2024, CISA and the FBI advised every Sisense customer to rotate credentials after attackers compromised the BI vendor's development environment — and by week's end, Sisense-issued AWS keys were circulating publicly. This piece reconstructs the five-day arc from detection to contained, explains why business-intelligence platforms are credential funnels that turn vendor CI/CD breaches into customer incidents, and extracts the third-party-risk doctrine the episode left behind for every embedded-analytics supply chain.

Continue ReadingSisense Breach: CI Credentials, AWS Keys and a CISA Advisory

CrushFTP VFS Sandbox Escape: Zero-Trust Patch Confusion in File Transfer

On April 19-20, 2024, CrushFTP shipped emergency fixes for CVE-2024-4040 — an unauthenticated escape from the virtual file system sandbox that exposed arbitrary host files, including the credential-stuffed configuration that anchors enterprise partner integrations. Exploitation followed within days, CISA listed it April 30, and a chaotic trail of interim builds left customers arguing about version numbers mid-fire. This account covers the traversal-to-escape chain, the mainserv credential hunt, and the hard lessons of small-vendor emergency patching.

Continue ReadingCrushFTP VFS Sandbox Escape: Zero-Trust Patch Confusion in File Transfer

PuTTY ECDSA Nonce Bias: How 71 Signatures Exposed Your SSH Key

PuTTY's April 2024 advisory for CVE-2024-31497 read like a physics problem: the terminal's ECDSA implementation biased nonces on NIST P-521, so roughly 71 captured SSH signatures suffice for a lattice attack that recovers the private key. This piece explains the Hidden Number Problem math, why archived PCAP and DLP session capture retroactively weaponized years of traffic, the 0.81 deterministic-nonce fix, and the brutal rotation drill that made every P-521 key used through Pageant presumptively burned.

Continue ReadingPuTTY ECDSA Nonce Bias: How 71 Signatures Exposed Your SSH Key

PAN-OS GlobalProtect Command Injection: April 2024’s Zero-Day Race (CVE-2024-3400)

On April 12, 2024, WatchTowr disclosed CVE-2024-3400 — a CVSS 10.0 pre-auth command injection in PAN-OS GlobalProtect that state-sponsored actors had exploited since late March by chaining a cookie-controlled file write into Tcl execution as root. This account walks the two-flaw exploit chain, the scramble after the 10.2.9-h1 hotfix, CISA's KEV clock, config-hidden persistence that survived reboots, the mitigation-versus-remediation confusion, and why 2024 made appliances patch with server-grade urgency.

Continue ReadingPAN-OS GlobalProtect Command Injection: April 2024’s Zero-Day Race (CVE-2024-3400)
>