Hmmnm
All articles published by

Hmmnm

Hands-on cybersecurity tutorials, CVE breakdowns, and guided learning paths. Every technique is explained, tested, and paired with its mitigation — so you learn the attack and the defense together.

Learning Paths · About Hmmnm · Editorial policy

CitrixBleed CVE-2023-4966: Session Tokens Straight From Memory

CVE-2023-4966 let attackers read valid session tokens out of NetScaler memory and inherit authenticated sessions wholesale — MFA already passed. CISA’s Emergency Directive 23-08 forced hunts and rebuilds as LockBit monetized the access.

Continue ReadingCitrixBleed CVE-2023-4966: Session Tokens Straight From Memory

LAPSUS$ Convictions: Teenagers, Helpdesks, and the GTA VI Leak

A London jury convicted the teenage LAPSUS$ hackers whose SIM swaps, MFA-fatigue pushes, and helpdesk manipulation breached Nvidia, Microsoft, Okta, Uber, and Rockstar — closing the criminal case that proved identity is the real perimeter.

Continue ReadingLAPSUS$ Convictions: Teenagers, Helpdesks, and the GTA VI Leak