Hmmnm
All articles published by

Hmmnm

Hands-on cybersecurity tutorials, CVE breakdowns, and guided learning paths. Every technique is explained, tested, and paired with its mitigation — so you learn the attack and the defense together.

Learning Paths · About Hmmnm · Editorial policy

Snowflake-Related Arrests: UNC5537’s Kitchener Pinch

On October 30, 2024, Canadian authorities arrested a 26-year-old Kitchener, Ontario man on a US warrant connecting him to the Snowflake-account intrusions tracked by Mandiant as UNC5537 — the crew behind the Ticketmaster, Santander, and AT&T disclosures that dominated 2024’s data-theft calendar. The arrest, first reported in early November by Bloomberg identifying the suspect as Connor Riley Moucka, illuminated the infostealer-credential-to-cloud kill chain and the market for stolen data. This account reconstructs the campaign, the arrest, and the MFA lessons that outlast it.

Continue ReadingSnowflake-Related Arrests: UNC5537’s Kitchener Pinch
Read more about the article EFB Regulations & Certification: FAA AC 120-76E, EASA AMC 20-25 & ICAO Doc 10020
Regulations and certification under FAA AC 120-76E, EASA AMC 20-25 and ICAO Doc 10020

EFB Regulations & Certification: FAA AC 120-76E, EASA AMC 20-25 & ICAO Doc 10020

EFB regulatory framework explained: FAA AC 120-76E/AC 91-78A, EASA AMC 20-25, ICAO Doc 10020, OpSpecs, Part-IS — and the operational approval process step by step.

Continue ReadingEFB Regulations & Certification: FAA AC 120-76E, EASA AMC 20-25 & ICAO Doc 10020

CVE-2024-10924: Really Simple Security’s 2FA Betrayal

On November 6, 2024, Wordfence researcher István Márton disclosed CVE-2024-10924 — a CVSS 9.8 authentication bypass in Really Simple Security, the plugin securing four million WordPress sites, whose two-factor onboarding endpoint failed to validate the requesting user, granting attackers admin sessions on sites with incomplete 2FA enrollment. Patched same-day in 9.1.2, NVD-published November 14, the flaw became 2024’s definitive case study in security-plugin risk. This account walks the vulnerable code path, the four-million-site patch sprint, and why the ecosystem’s auth surface extends far past WordPress core.

Continue ReadingCVE-2024-10924: Really Simple Security’s 2FA Betrayal

Tool Hijacking: The 2024 Papers That Predicted Agent Attacks

By November 2024, AI-agent security research had already documented the attack class that production incidents would later make infamous. InjecAgent (March 2024, ACL Findings) benchmarked 1,054 indirect-injection scenarios across 30 agents, finding ReAct-prompted GPT-4 attacked successfully roughly a quarter of the time. Breaking Agents (July 2024) demonstrated malfunction amplification through agentic loops. Together with 2023’s foundational indirect-prompt-injection work, they mapped how tools, descriptions, and fetched content become command channels. This survey walks the papers, the hijack taxonomy, and the controls that predate the incidents.

Continue ReadingTool Hijacking: The 2024 Papers That Predicted Agent Attacks

NIST’s PQC Standards: FIPS 203-205 and the Migration Clock

On August 13, 2024, NIST published the final versions of FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) — the first formal post-quantum cryptography standards, capping an eight-year open competition and starting the migration clock for RSA and elliptic-curve infrastructure. With harvest-now-decrypt-later collection already threatening long-lived secrets and federal migration timelines targeting the 2030s, enterprises face a decade-scale cryptographic inventory and replacement program. This guide walks the standards, the threat math, and the migration playbook from inventory to hybrid deployment.

Continue ReadingNIST’s PQC Standards: FIPS 203-205 and the Migration Clock

Kadrey v. Meta: Piracy Allegations and the Llama Paper Trail

In mid-December 2024, unsealed filings in Kadrey et al. v. Meta Platforms alleged the company torrented LibGen’s pirated library while engineers warned it ‘doesn’t feel right’ on corporate laptops, stripped copyright management information with purpose-built scripts, and used a dataset a memo called ‘we know to be pirated’ — with CEO approval over executive objections. The proposed DMCA and CDAFA claims reframe the AI-copyright fight around distribution and concealment rather than fair use alone. This account walks the exhibits, the legal architecture, and the compliance lessons for every AI data program.

Continue ReadingKadrey v. Meta: Piracy Allegations and the Llama Paper Trail

Travelex Ransomware 2020: When Sodinokibi Crippled a Currency Giant

On 31 December 2019, foreign exchange giant Travelex took its UK and international websites and mobile apps offline following a cyberattack, an outage that also knocked out white-label travel money services at ASDA, Tesco and Sainsbury’s overnight. When the story became public on 7 January 2020, the criminals behind Sodinokibi (REvil) ransomware were demanding 4.6 million pounds, claiming to have copied more than 5GB of customer data, and the company would spend weeks rebuilding systems by hand. This account reconstructs the verified timeline, the double-extortion playbook, and how the incident contributed to an August 2020 administration that cut more than a thousand UK jobs.

Continue ReadingTravelex Ransomware 2020: When Sodinokibi Crippled a Currency Giant

CurveBall CVE-2020-0601: Forging Trust With One Elliptic Curve Parameter

On 14 January 2020, Microsoft’s first Patch Tuesday of the decade included a fix for CVE-2020-0601, a cryptographic implementation flaw in Windows CryptoAPI reported to the vendor by the U.S. National Security Agency. The bug let anyone forge TLS certificates that appeared to chain to the U.S. government’s ECC trusted root, making malicious HTTPS sites look legitimately signed. Researchers named it CurveBall, proof-of-concept exploits appeared within days, and CISA issued Emergency Directive 20-02 ordering federal agencies to hunt and patch. This is the story of how a single mishandled curve parameter undermined certificate trust Windows-wide.

Continue ReadingCurveBall CVE-2020-0601: Forging Trust With One Elliptic Curve Parameter

Internet Explorer CVE-2020-0674: The Zero-Day Advisory That Opened 2020

On 17 January 2020, Microsoft published ADV200001, a rare out-of-band advisory for CVE-2020-0674, a remote code execution flaw in the scripting engine used by Internet Explorer 9 and 11 that the company confirmed was being exploited in limited targeted attacks. There was no patch yet, only mitigations and workarounds, and defenders spent nearly a month exposed until the 11 February 2020 cumulative update shipped the fix. This piece reconstructs the advisory, the memory-corruption mechanics in the script engine, why IE was still a live attack surface in 2020, and what the episode taught about mitigations-first disclosure.

Continue ReadingInternet Explorer CVE-2020-0674: The Zero-Day Advisory That Opened 2020

After Soleimani: The January 2020 US-Iran Cyber Alert Wave

Within hours of the 3 January 2020 strike that killed Iranian general Qasem Soleimani, security agencies on both sides of the Atlantic braced for cyber retaliation. On 6 January 2020 a U.S. federal website, the Federal Depository Library Program, was defaced with pro-Iran messaging and an image of a bloodied President Trump, claimed by a group calling itself Iran Silk Hat, while CISA and the FBI renewed warnings about possible Iranian attacks on critical infrastructure. This retrospective maps the verified incidents of that week, separates hype from evidence, and explains why agencies treated the moment as a genuine escalation trigger despite limited actual damage.

Continue ReadingAfter Soleimani: The January 2020 US-Iran Cyber Alert Wave

Exchange CVE-2020-0688: A Default Key Made Every Server Alike

On 11 February 2020, Microsoft disclosed CVE-2020-0688, a remote code execution vulnerability in Microsoft Exchange Server’s Unified Messaging service that scored 9.8 on CVSS because every installation shipped with the same cryptographic validation key by default. Any authenticated user could send a specially crafted viewstate to the Exchange Control Panel and achieve RCE as SYSTEM, and because service accounts and weak credentials were everywhere, authenticated was a low bar. This analysis walks the vulnerable request path, the viewstate forgery mechanics, the patch, and the long tail of scanning and exploitation that followed for months.

Continue ReadingExchange CVE-2020-0688: A Default Key Made Every Server Alike

Clearview AI in 2020: Three Billion Scraped Faces, One Leaked Client List

In late February 2020, facial recognition startup Clearview AI confirmed that a misconfigured server had exposed its entire client list, days after a major newspaper investigation revealed the company had scraped more than three billion facial images from social networks and the open web to sell face search to police. The leaked list showed U.S. retailers, banks, and investors among users of a tool built on photos most people never knowingly gave. Cease-and-desist letters from Facebook and other platforms followed, along with GDPR complaints across Europe. This is how facial recognition’s most aggressive company lost control of its own story in a matter of weeks.

Continue ReadingClearview AI in 2020: Three Billion Scraped Faces, One Leaked Client List