Hmmnm
All articles published by

Hmmnm

Hands-on cybersecurity tutorials, CVE breakdowns, and guided learning paths. Every technique is explained, tested, and paired with its mitigation — so you learn the attack and the defense together.

Learning Paths · About Hmmnm · Editorial policy

ConnectWise ScreenConnect Auth Bypass: An Instant RCE Wave

February 2024’s CVE-2024-1709 let anyone add administrative accounts to self-hosted ScreenConnect servers — a setup-wizard path traversal that converted remote-support consoles into ransomware deployment platforms within 72 hours of disclosure. This account covers the twinned vulnerabilities, why MSP-hosted instances multiplied the blast radius across client fleets, the observed ransomware sequences, and the hard questions RMM vendors faced about unauthenticated wizard endpoints.

Continue ReadingConnectWise ScreenConnect Auth Bypass: An Instant RCE Wave

Wyze Camera Flaw: 13,000 Strangers Through One Caching Hole

Two February 2024 vulnerabilities let Wyze app users briefly see thumbnails and live feeds of strangers’ cameras — a cache-key failure amplified by a three-year-old flaw resurfacing in redesigned hardware. This account covers the date-based cache-key bug, the 13,000 affected users, the nine-hour fleet update, and the uncomfortable questions about budget-camera security engineering when the same vendor has now repeated the vulnerability class.

Continue ReadingWyze Camera Flaw: 13,000 Strangers Through One Caching Hole

AnyDesk Breach: Production Compromise and a Certificate Sprint

Remote-access maker AnyDesk confirmed in February 2024 that attackers had compromised production systems using valid credentials traced to infostealer logs — forcing a certificate rotation, password resets, and a rushed 8.1.1 release whose code-signing was intact but whose credibility needed rebuilding. This piece covers the infostealer-to-supply-chain escalation path that rewired vendor-risk thinking, and why remote-admin tooling became a tier-one identity perimeter.

Continue ReadingAnyDesk Breach: Production Compromise and a Certificate Sprint

MOAB: The 26 Billion-Record Compilation That Wasn’t a Breach

The January 2024 ‘Mother of All Breaches’ headline turned out to be a compilation of thousands of prior incidents re-hosted in a misconfigured bucket — 26 billion rows of recycled credentials stacked into a credential-stuffing goldmine. This piece explains why aggregations are not new breaches but still multiply risk, how the 12-terabyte trove mapped to old LinkedIn, Adobe and MyFitnessPal leaks, and why password reuse makes every old breach a live 2024 attack.

Continue ReadingMOAB: The 26 Billion-Record Compilation That Wasn’t a Breach

Ivanti Connect Secure Zero-Days: The Edge-Appliance Crisis

January 2024 opened with the year’s first appliance crisis: two pre-authentication zero-days in Ivanti Connect Secure that nation-state actors had already exploited, followed by integrity-check failures and a reset wave across thousands of enterprise VPNs. This account covers CVE-2023-46805 and CVE-2024-21887, the mass exploitation between disclosure and patch, the customers whose breaches surfaced weeks later, and why edge appliances became the year’s most contested patch surface.

Continue ReadingIvanti Connect Secure Zero-Days: The Edge-Appliance Crisis

SMTP Smuggling: Spoofing Email With Authenticated Mail

December 2023 brought one of email’s most elegant attacks: SMTP smuggling, a parser-level desync that tricks receiving servers into writing attacker-authored messages that pass SPF and DMARC because the victim’s own infrastructure vouches for them. This deep dive covers the technique mechanics (end-of-data ambiguity, the second hidden MAIL FROM conversation), the December 19 disclosure and DHL demonstration, the two anchoring CVEs, which product families patched, and the durable lessons for mail admins running anything that speaks SMTP.

Continue ReadingSMTP Smuggling: Spoofing Email With Authenticated Mail

Apple’s iOS 17.2 Bluetooth Fixes vs the Flipper Zero Craze

December 2023’s patch wave closed the chapter on a strange season: cheap programmable gadgets spraying Bluetooth frames in public, iPhones crashing in viral videos, and Apple shipping denial-of-service fixes in the iOS 17.2 family. This piece explains the crash-pair CVEs, why Bluetooth’s design makes every phone an always-on parser for stranger traffic, how the December 20 advisory window anchored the fixes, and why proximity protocols remain a permanent hardening frontier for every device maker.

Continue ReadingApple’s iOS 17.2 Bluetooth Fixes vs the Flipper Zero Craze

DP World Australia: When a Cyber Incident Stopped the Cranes

On 13 November 2023, DP World Australia disconnected its port systems from the internet to contain an intrusion — and container operations at Sydney, Melbourne, Brisbane and Fremantle stopped cold, stranding roughly 30,000 containers for three days. Operations resumed by 16 November, personnel data exposure was later confirmed, and no ransom payment was disclosed. The episode became Australia’s reference case for cyber-driven supply-chain disruption and a model of disciplined containment, rapid restoration and honest capacity communication under SOI-Act scrutiny.

Continue ReadingDP World Australia: When a Cyber Incident Stopped the Cranes

ownCloud CVE-2023-49103: The CVSS 10.0 in the Docker Image

The graphapi app bundled in ownCloud’s Docker deployment images exposed mail credentials, database passwords, and S3 keys to unauthenticated visitors — a mis-packaged dependency that became full infrastructure compromise. CISA KEV-listed it within ten days.

Continue ReadingownCloud CVE-2023-49103: The CVSS 10.0 in the Docker Image

ChatGPT’s November 2023 DDoS Outages, Explained

For much of 8 November 2023, ChatGPT and parts of OpenAI’s API cycled in and out of service under a denial-of-service wave claimed by Anonymous Sudan, with smaller recurrences through the month. OpenAI confirmed the DDoS, rolled global WAF rules, and absorbed a false-positive tax on legitimate users. Nothing was breached — the story is availability risk wrapped around AI dependence. This post walks the campaign’s anatomy, Microsoft’s Storm-1359 telemetry link, and the business-continuity lessons for anyone running on AI vendors.

Continue ReadingChatGPT’s November 2023 DDoS Outages, Explained

LockBit, CitrixBleed, and the ICBC Treasury Hack

When LockBit hit ICBC’s US broker-dealer on 9 November 2023, Treasury-market connectivity went dark and manual settlement took over for days. The entry path traced to CitrixBleed session tokens stolen before the October patch and never invalidated — exactly what CISA’s Emergency Directive 23-08 had warned. LockBit claimed a roughly $9 million ransom demand, never verified. The post walks the token-replay kill chain, the disclosure-era aftermath, and the defensive lesson that remediation includes revocation.

Continue ReadingLockBit, CitrixBleed, and the ICBC Treasury Hack

F5 BIG-IP Request Smuggling 2023: The 9.8 Desync

CVE-2023-46747 let unauthenticated attackers smuggle requests through BIG-IP TMM into the iControl REST management plane — a framing bug that became full device compromise. Exploitation followed the October patch within days, and CISA put it on the KEV catalog before month end.

Continue ReadingF5 BIG-IP Request Smuggling 2023: The 9.8 Desync