Hmmnm
All articles published by

Hmmnm

Hands-on cybersecurity tutorials, CVE breakdowns, and guided learning paths. Every technique is explained, tested, and paired with its mitigation — so you learn the attack and the defense together.

Learning Paths · About Hmmnm · Editorial policy

CDK Global Ransomware: US Car Dealerships Run on Pen and Paper

On June 19, 2024, ransomware hit CDK Global’s dealer management platform — the operational nervous system of ~15,000 North American dealerships — and a second strike during recovery extended the outage for weeks while finance desks, service bays and OEM ordering reverted to paper and fax. This account covers the June 19/22 double-hit timeline, the billion-dollar industry loss estimates, why DMS lock-in made fallback manual rather than competitive, and the concentration-risk docket the incident left for every regulator to cite.

Continue ReadingCDK Global Ransomware: US Car Dealerships Run on Pen and Paper

Squarespace Domain Hijackings: The 2024 GoDaddy Migration Aftermath

After Squarespace absorbed roughly 10 million domains from Google Domains in mid-2024, attackers discovered a seam: legacy Google-account login flows stopped being enforced, and formerly eNom-transferred .dev/.us domains could be taken over by re-registering then-unlinked accounts. From late June through July, crypto-draining hijacks of high-value domains — including Matomo founder trust abusing Squarespace lock states — left registry operators and site owners scrambling. This account traces the migration mechanics, the attack window, and the DNS tenure lessons.

Continue ReadingSquarespace Domain Hijackings: The 2024 GoDaddy Migration Aftermath

Magecart’s 2024 Resurgence: Skimming in the Polyfill.io Aftermath

Through 2024, digital skimming returned to threat reports’ front pages: Magecart-style attacks compromised hundreds of storefronts via compromised third-party JavaScript, supply-chain infections like polyfill.io’s June domain takeover injected malicious scripts into vast numbers of pages, and PCI DSS 4.0’s script-integrity requirements (6.4.3 and 11.6.2) approached their March 2025 enforcement deadline. This survey digests the modern skimming kill chain — injection, exfiltration, and evasion — the major 2024 campaigns, and the compliance clock turning client-side risk into boardroom math.

Continue ReadingMagecart’s 2024 Resurgence: Skimming in the Polyfill.io Aftermath