>

AT&T 73M Leak: The 2019 Dataset That Resurfaced Free

March 2024's 73-million-record AT&T leak was an old wound reopened: a 2019-era vendor-workspace dataset, shopped unsuccessfully in 2021, finally dumped free on a hacking forum with SSNs and account details intact. This account disentangles it from the concurrent Snowflake campaign, explains why free publication maximizes criminal utility, maps the 7.6 million passcode resets, and follows the extortion thread that later surfaced in DOJ filings.

Continue ReadingAT&T 73M Leak: The 2019 Dataset That Resurfaced Free

The XZ Utils Backdoor: Inside the Almost-Catastrophe

The most patient supply-chain attack ever caught — a two-year maintainer infiltration that planted an SSH backdoor into xz-utils release tarballs, discovered in March 2024 only because one engineer noticed 500 milliseconds of latency. This account traces the Jia Tan persona from helpful contributor to release engineer, the test-file obfuscation and build-stage injection, the systemd/sshd target chain, the near-miss that kept stable distros clean, and the trust-model reforms that rippled through open source.

Continue ReadingThe XZ Utils Backdoor: Inside the Almost-Catastrophe

Ray AI Framework’s ‘Won’t Fix’ CVEs: A Control-Plane Debate

When Protect AI disclosed five Ray vulnerabilities in March 2024 — including critical RCE via the unauthenticated control plane — Anyscale's 'won't fix, trusted-networks design' stance ignited the year's sharpest debate over AI infrastructure responsibility. This piece unpacks the job-submission RCE, the exposed-cluster census, the bounty economics, what Anyscale later shipped anyway, and the hardening playbook that became standard for every exposed ML control plane.

Continue ReadingRay AI Framework’s ‘Won’t Fix’ CVEs: A Control-Plane Debate

JetBrains TeamCity Auth Bypass: Build Servers as Front Door

March 2024's CVE-2024-27198 let unauthenticated attackers mint admin accounts on self-hosted TeamCity CI servers, converting every connected build agent into attacker-controlled execution holding source, secrets and signing keys. This piece covers the alternate-path authentication bypass, the companion path traversal, the ransomware crews that queued within days, and the year's hard-learned rule that build infrastructure deserves domain-controller-grade security.

Continue ReadingJetBrains TeamCity Auth Bypass: Build Servers as Front Door

LockBit Takedown: Operation Cronos and Its Awkward Aftermath

February 2024's Operation Cronos seized LockBit's infrastructure across a dozen countries — and then the leaks showed how long the FBI had been inside. This account covers the covert access, the sting timing driven by UK hospital targeting, the servers and affiliate accounts taken down, the hurried rebrand to LockBit 4.1, the affiliate diaspora to RansomHub and Akira, and the awkward questions the takedown's trolling raised about reading crime statistics.

Continue ReadingLockBit Takedown: Operation Cronos and Its Awkward Aftermath

Change Healthcare ALPHV: The Ransomware That Broke US Healthcare

One ALPHV/BlackCat intrusion in February 2024 froze claims and pharmacy payments across US healthcare for weeks — the single most consequential ransomware attack of the year. This account covers the nine-day dwell time, the $22 million ransom payment and the exit-scam double-cross that brought RansomHub back for seconds, the eventual disclosure of hundreds of millions of records, and why one processor's central position converted a single encryptor into a national healthcare liquidity crisis.

Continue ReadingChange Healthcare ALPHV: The Ransomware That Broke US Healthcare

ConnectWise ScreenConnect Auth Bypass: An Instant RCE Wave

February 2024's CVE-2024-1709 let anyone add administrative accounts to self-hosted ScreenConnect servers — a setup-wizard path traversal that converted remote-support consoles into ransomware deployment platforms within 72 hours of disclosure. This account covers the twinned vulnerabilities, why MSP-hosted instances multiplied the blast radius across client fleets, the observed ransomware sequences, and the hard questions RMM vendors faced about unauthenticated wizard endpoints.

Continue ReadingConnectWise ScreenConnect Auth Bypass: An Instant RCE Wave

Wyze Camera Flaw: 13,000 Strangers Through One Caching Hole

Two February 2024 vulnerabilities let Wyze app users briefly see thumbnails and live feeds of strangers' cameras — a cache-key failure amplified by a three-year-old flaw resurfacing in redesigned hardware. This account covers the date-based cache-key bug, the 13,000 affected users, the nine-hour fleet update, and the uncomfortable questions about budget-camera security engineering when the same vendor has now repeated the vulnerability class.

Continue ReadingWyze Camera Flaw: 13,000 Strangers Through One Caching Hole

AnyDesk Breach: Production Compromise and a Certificate Sprint

Remote-access maker AnyDesk confirmed in February 2024 that attackers had compromised production systems using valid credentials traced to infostealer logs — forcing a certificate rotation, password resets, and a rushed 8.1.1 release whose code-signing was intact but whose credibility needed rebuilding. This piece covers the infostealer-to-supply-chain escalation path that rewired vendor-risk thinking, and why remote-admin tooling became a tier-one identity perimeter.

Continue ReadingAnyDesk Breach: Production Compromise and a Certificate Sprint

MOAB: The 26 Billion-Record Compilation That Wasn’t a Breach

The January 2024 'Mother of All Breaches' headline turned out to be a compilation of thousands of prior incidents re-hosted in a misconfigured bucket — 26 billion rows of recycled credentials stacked into a credential-stuffing goldmine. This piece explains why aggregations are not new breaches but still multiply risk, how the 12-terabyte trove mapped to old LinkedIn, Adobe and MyFitnessPal leaks, and why password reuse makes every old breach a live 2024 attack.

Continue ReadingMOAB: The 26 Billion-Record Compilation That Wasn’t a Breach

Midnight Blizzard vs Microsoft: Legacy Tenant to Executive Email

A defunct test tenant, a legacy password without MFA, and a residential-proxy password spray gave Russia's Midnight Blizzard a foothold inside Microsoft's own corporate estate in January 2024 — culminating in stolen executive email and a downstream supplier breach wave. This account explains the password-spray tradecraft, how the actors abused OAuth apps to mine mailboxes, why the failure drew a czar-memo mea culpa, and the SEC disclosure mechanics that made the saga public.

Continue ReadingMidnight Blizzard vs Microsoft: Legacy Tenant to Executive Email

Ivanti Connect Secure Zero-Days: The Edge-Appliance Crisis

January 2024 opened with the year's first appliance crisis: two pre-authentication zero-days in Ivanti Connect Secure that nation-state actors had already exploited, followed by integrity-check failures and a reset wave across thousands of enterprise VPNs. This account covers CVE-2023-46805 and CVE-2024-21887, the mass exploitation between disclosure and patch, the customers whose breaches surfaced weeks later, and why edge appliances became the year's most contested patch surface.

Continue ReadingIvanti Connect Secure Zero-Days: The Edge-Appliance Crisis
>