Hmmnm
All articles published by

Hmmnm

Hands-on cybersecurity tutorials, CVE breakdowns, and guided learning paths. Every technique is explained, tested, and paired with its mitigation — so you learn the attack and the defense together.

Learning Paths · About Hmmnm · Editorial policy

F5 BIG-IP Next Central Manager: The Unauthenticated Takeover Bugs

On November 6, 2024, F5 disclosed a pair of critical bugs in BIG-IP Next Central Manager shipped in its SPK fabric: CVE-2024-23327, an unauthenticated privilege-escalation path reachable via REST API, and CVE-2024-23328, a missing-authentication flaw letting attackers create arbitrary administrator accounts. Together they enable full takeover of a management node that itself commands a fleet of application delivery hardware. This account walks both paths, the same-day patches, and the uncomfortable lineage going back to CVE-2022-1388’s iControl REST flaw.

Continue ReadingF5 BIG-IP Next Central Manager: The Unauthenticated Takeover Bugs

Ivanti Endpoint Manager RCE: Two Bugs, One Dangerous Chain

On October 16, 2024, Ivanti disclosed two vulnerabilities in Endpoint Manager (EPM) chained for pre-auth remote code execution: CVE-2024-29224, an unauthenticated SSRF rated 9.6, and CVE-2024-29226, a path traversal in a downstream service. The week’s disclosure calendar placed it days after FortiManager’s FortiJump and amid a year of Ivanti security crises — from January’s Connect Secure zero-days to September’s Cloud Service Appliance flaw. This account explains the chain mechanics, why consortium defenders pushed urgent patching, and the management-plane pattern of 2024.

Continue ReadingIvanti Endpoint Manager RCE: Two Bugs, One Dangerous Chain

FortiManager Zero-Day (FortiJump): CISA Escalation Explained

On October 23, 2024, Fortinet confirmed CVE-2024-47575 — a CVSS 9.8 missing-authentication flaw in the FortiManager FGFM protocol that China-nexus actor UNC5850 had exploited since summer to jump from exposed managers into fleets of managed FortiGates with a custom DeepMove implant. CISA KEV-listed it within days, forcing two-week patch deadlines across federal and enterprise fleets. This account reconstructs the protocol bug, the DeepMove persistence, the fleet-jump blast radius, and the management-plane hardening it made mandatory.

Continue ReadingFortiManager Zero-Day (FortiJump): CISA Escalation Explained

CUPS RCE: The Linux Printing Story That Went Viral Before CVEs Landed

In late September 2024, researcher Simone Margaritelli disclosed a chain of CUPS vulnerabilities — CVE-2024-47076, CVE-2024-47176 and siblings — allowing same-network attackers to register malicious printers and achieve code execution as the lp user via broadcast-trusting auto-configuration. Preceded by a hype-teaser countdown that split the community, the episode became the year’s clearest study in disclosure-process dysfunction, severity theater, and the quiet ubiquity of trust-the-LAN daemons. This account covers the chain mechanics, the honest exposure math, and what to disable today.

Continue ReadingCUPS RCE: The Linux Printing Story That Went Viral Before CVEs Landed

TfL 2024: A 17-Year-Old, a Social Engineer’s Approach and Oyster Chaos

On September 5, 2024, Transport for London detected an intrusion begun days earlier through social engineering of staff — and within a week a 17-year-old was arrested, then charged under the Computer Misuse Act, for a breach that exposed contact details and the bank details of roughly 3,000 Oyster refund customers. This account reconstructs the phishing entry, the lateral movement, the containment that took status boards and the refund portal offline, the NCSC-NCA response, and the municipal-security lessons that outlasted the headlines.

Continue ReadingTfL 2024: A 17-Year-Old, a Social Engineer’s Approach and Oyster Chaos

SolarWinds Web Help Desk RCE: The Name That Hurts Again

On August 21-22, 2024, SolarWinds shipped 12.8.3 HF1 for Web Help Desk and disclosed CVE-2024-28986 — an unauthenticated Java deserialization flaw rated CVSS 9.8 that delivers pre-auth remote code execution on internet-facing instances. Within days PoC code circulated in exploitation attempts, and on August 26 CISA added it to the Known Exploited Vulnerabilities catalog, making patching mandatory across federal networks. This account covers the bug mechanics, the four-day disclosure-to-KEV sprint, and the uncomfortable optics of a SolarWinds product back in emergency-cycle headlines.

Continue ReadingSolarWinds Web Help Desk RCE: The Name That Hurts Again

The Telegram Arrest and the Encryption Debate of 2024

On August 24, 2024, French authorities arrested Telegram founder Pavel Durov at Le Bourget airport, and two days later charged him with complicity in organized-crime offenses enabled by his platform’s refusal to cooperate with legal process — the first time a major encrypted-service executive faced criminal liability for governance choices. Released under judicial supervision within days, Durov’s case forced every platform lawyer to reprice jurisdictional arbitrage, moderation staffing, and the meaning of cooperation. This account lays out the charges, the encryption-policy fault lines, and the compliance playbook that followed.

Continue ReadingThe Telegram Arrest and the Encryption Debate of 2024

Windows Downdate: Downgrade Attacks Against the OS Itself

At DEF CON 32 in August 2024, SafeBreach’s Alon Leviev unveiled Downdate — a technique that abuses the Windows Modules Installer, TrustedInstaller privileges,and deliberately-eased vbsm manifest permission to silently roll back fully-patched Windows binaries to vulnerable prior versions, re-opening fixed BitLocker bypasses and Hyper-V escapes on current builds. This account explains the downgrade mechanics, the CVE-2024-21430 fix timeline, and why the research redefined patch currency as a security property worth defending.

Continue ReadingWindows Downdate: Downgrade Attacks Against the OS Itself

National Public Data: 2.9B SSN Records for the Price of a Breach

In August 2024, national background-check broker National Public Data confirmed a breach that leaked roughly 2.9 billion rows of personal records — names, addresses, relatives, SSNs — covering plausibly every US adult and parts of the UK and Canada, after a criminal actor first offered the data for sale in April and a third party then dumped 277GB free. This account traces the broker supply chain that assembled the dossier, the class-action lawsuit that forced acknowledgment, and the post-SSN security posture every organization now needs.

Continue ReadingNational Public Data: 2.9B SSN Records for the Price of a Breach

CrowdStrike Falcon Outage: 8.5M Hosts & Fragile Architecture

On July 19, 2024, a routine sensor configuration update from CrowdStrike passed staged testing and rolled through the Falcon channel to roughly 8.5 million Windows hosts — and crashed them into Blue Screens of Death, grounding flights, halting broadcasters and hospitals in the largest IT outage in history. This account reconstructs the flawed content-deployment pipeline, the Channel File 291 logic that sent the kernel into chaos, the 78-minute Remediation and guidance HHCfollows, the blame theater that followed, and why the incident rewrote every argument about single-vendor concentration risk.

Continue ReadingCrowdStrike Falcon Outage: 8.5M Hosts & Fragile Architecture

AT&T’s Snowflake Ransom Payment: The $370K Precedent

On July 31, 2024, AT&T confirmed its customer data — including call and text metadata of nearly all subscribers and some SSNs — had been stolen off Snowflake’s cloud via compromised service-account credentials, and that it had paid roughly $370,000 to the SQlMap-scanning crew known as ShinyHunters to delete it. This account reconstructs the credential theft, the infostealer-to-Snowflake kill chain, the economics of a mid-six-figure ransom, and the quarterly-burial of accountability between carrier, and its data-warehouse vendor.

Continue ReadingAT&T’s Snowflake Ransom Payment: The $370K Precedent

APT29 Inside TeamViewer: 2024’s Calmest, Most Instructive Breach

On June 28, 2024, TeamViewer disclosed that a state-sponsored actor — widely reported as Russia’s APT29 — had breached its corporate IT network through a standard employee’s credentials, and that the remote-access product itself, and every customer, stayed untouched. This account reconstructs the hours-to-containment timeline, explains why corporate/product segmentation carried the day, places the intrusion in Cozy Bear’s patient espionage season, and draws the anti-SolarWinds comparison that made this 2024’s most instructive breach.

Continue ReadingAPT29 Inside TeamViewer: 2024’s Calmest, Most Instructive Breach