Hmmnm
All articles published by

Hmmnm

Hands-on cybersecurity tutorials, CVE breakdowns, and guided learning paths. Every technique is explained, tested, and paired with its mitigation — so you learn the attack and the defense together.

Learning Paths · About Hmmnm · Editorial policy

Change Healthcare ALPHV: The Ransomware That Broke US Healthcare

One ALPHV/BlackCat intrusion in February 2024 froze claims and pharmacy payments across US healthcare for weeks — the single most consequential ransomware attack of the year. This account covers the nine-day dwell time, the $22 million ransom payment and the exit-scam double-cross that brought RansomHub back for seconds, the eventual disclosure of hundreds of millions of records, and why one processor’s central position converted a single encryptor into a national healthcare liquidity crisis.

Continue ReadingChange Healthcare ALPHV: The Ransomware That Broke US Healthcare

MGM, Caesars, and Scattered Spider: The Vishing Fall of 2023

In September 2023 Scattered Spider vished the MGM helpdesk, pivoted through Okta to ESXi, and detonated ALPHV ransomware — a $100M quarter for MGM while Caesars paid up. The reference incident for helpdesk verification, MFA fatigue, and pay-vs-rebuild economics.

Continue ReadingMGM, Caesars, and Scattered Spider: The Vishing Fall of 2023

Cisco BroadWorks CVE-2023-20237: The SSO Bypass Scare

In September 2023 Cisco rushed out patches for CVE-2023-20237, a critical authentication bypass in BroadWorks’ single-sign-on flows that could let attackers authenticate as any user. With evidence of active scanning, carrier admins ran an emergency patch marathon.

Continue ReadingCisco BroadWorks CVE-2023-20237: The SSO Bypass Scare

Storm-0558 Forged-Token Breach: The Stolen Key That Read Government Email

China-linked Storm-0558 forged Azure AD tokens with a stolen Microsoft consumer signing key and read email at ~25 organizations including the State and Commerce departments — exposing vendor key hygiene, token scope validation, and log-tiering as board-level security questions.

Continue ReadingStorm-0558 Forged-Token Breach: The Stolen Key That Read Government Email