GoDaddy’s Multi-Year cPanel Breach: 2.5 Years of Dwell
GoDaddy’s 2023 filing admitted intermittent intruder access since 2020, malware in cPanel servers, and email interception affecting ~6.95M customers.
Hands-on cybersecurity tutorials, CVE breakdowns, and guided learning paths. Every technique is explained, tested, and paired with its mitigation — so you learn the attack and the defense together.
GoDaddy’s 2023 filing admitted intermittent intruder access since 2020, malware in cPanel servers, and email interception affecting ~6.95M customers.
ESXiArgs hit thousands of unpatched VMware ESXi hosts via old OpenSLP bugs in February 2023. Hypervisor ransomware and recovery-script lessons.
A single compromised API credential let an actor scrape ~37 million T-Mobile accounts over six weeks. Machine-identity governance lessons from a repeat offender.
CVE-2023-24055 showed a config-planted trigger could export KeePass vaults in plaintext after unlock. The debate: feature, flaw, or threat model?
CVE-2023-4966 let attackers read valid session tokens out of NetScaler memory and inherit authenticated sessions wholesale — MFA already passed. CISA’s Emergency Directive 23-08 forced hunts and rebuilds as LockBit monetized the access.
In September 2023 two extortion crews — Rhysida and the short-lived Ransomed.vc — both posted Sony data claims, complete with a Bitcoin auction and a leaked code-signing certificate. Sony investigated; the claimed 6TB scale never verified.
A London jury convicted the teenage LAPSUS$ hackers whose SIM swaps, MFA-fatigue pushes, and helpdesk manipulation breached Nvidia, Microsoft, Okta, Uber, and Rockstar — closing the criminal case that proved identity is the real perimeter.
Ransomware forced the Guardian’s newsroom off its networks for weeks in late 2022 — yet print and web kept publishing. Editorial continuity lessons.
SVB’s March 2023 run froze payroll for half of venture-backed tech and minted a fraud wave targeting displaced customers. Treasury continuity lessons.
A cloned intranet page harvested an employee’s password and MFA code, opening hours of internal access. Phishing-resistant MFA and self-report lessons.
LockBit encrypted Royal Mail’s international sorting operations in January 2023 and demanded $80M. Royal Mail paid nothing and kept the letters moving.
Rackspace’s December 2022 ransomware incident took Hosted Exchange down for weeks, ended the product’s life, and cost $12M+. Legacy platform lessons.