>

Marriott’s FTC Settlement: 20 Years of Audits for Starwood’s Ghosts

On October 9, 2024, the FTC announced a pair of consent orders — Marriott and its Starwood subsidiary — resolving claims that skimped security contributed to the 2014-2018 Starwood intrusions and a 2018 breach affecting over 131 million consumers from which attackers extracted 5.25 million unencrypted passport numbers. The order imposes 20 years of independent assessments and a claims program offering $150 cash orotomy spending on security — close kin to the UK ICO's £18.4M fine and the states' $52M settlement. This account traces the 2014→2018 intrusion, the regulatory pile-on, and what a two-decade oversight tail teaches about inherited security debt.

Continue ReadingMarriott’s FTC Settlement: 20 Years of Audits for Starwood’s Ghosts

Internet Archive Breach and DDoS: 31M Accounts, One Pop-Up

On October 9, 2024, visitors to the Internet Archive's Wayback Machine were greeted by an injected JavaScript pop-up announcing the compromise of 31,081,179 user accounts — the HIBP-confirmed count of the organization's authentication database, loaned from a September exposure of its Zendesk support portal. A concurrent DDoS attributed to SN_BlackMeta compounded the disruption; days later, archived XSS attempts confirmed the org'sJavaScript security debt. This account traces the initial access, the pop-up's evidence chain, and the funding-and-fragility story of a library built on hope.

Continue ReadingInternet Archive Breach and DDoS: 31M Accounts, One Pop-Up

Cisco SSM On-Prem Flaws: CVSS 10.0 and a CLI Zero-Day in One Week

In early October 2024, Cisco's disclosure cadence stacked two unrelated but equally urgent problems: CVE-2024-20419, a CVSS 10.0 unauthenticated password-change flaw in Smart Software Manager On-Prem that let anyone with network access reset the admin API account, and CVE-2024-20399, a CLI command-injection bug in NX-OS already being exploited in the wild per the CISA KEV catalog. This account reconstructs both flaws' mechanics, the patch timelines, and what this pairing says about authentication surface area in management tooling.

Continue ReadingCisco SSM On-Prem Flaws: CVSS 10.0 and a CLI Zero-Day in One Week

CUPS RCE: The Linux Printing Story That Went Viral Before CVEs Landed

In late September 2024, researcher Simone Margaritelli disclosed a chain of CUPS vulnerabilities — CVE-2024-47076, CVE-2024-47176 and siblings — allowing same-network attackers to register malicious printers and achieve code execution as the lp user via broadcast-trusting auto-configuration. Preceded by a hype-teaser countdown that split the community, the episode became the year's clearest study in disclosure-process dysfunction, severity theater, and the quiet ubiquity of trust-the-LAN daemons. This account covers the chain mechanics, the honest exposure math, and what to disable today.

Continue ReadingCUPS RCE: The Linux Printing Story That Went Viral Before CVEs Landed

Kia’s Web Portal: Register Any Car’s Account, Control It From Your Phone

On September 25, 2024, researchers Karan Saini and Sam Curry published an access-control flaw in Kia's dealer and consumer web infrastructure: given only a license plate, an attacker could register an account with remote lock, unlock, start, stop, locate and horn control over 2014-2025 connected vehicles they did not own. Kia patched in August before disclosure. This account walks the plate-to-command chain, the ownership-verification gap, the threat model for tracking and theft, and the automotive-API authorization lesson that outlasts the brand.

Continue ReadingKia’s Web Portal: Register Any Car’s Account, Control It From Your Phone

TfL 2024: A 17-Year-Old, a Social Engineer’s Approach and Oyster Chaos

On September 5, 2024, Transport for London detected an intrusion begun days earlier through social engineering of staff — and within a week a 17-year-old was arrested, then charged under the Computer Misuse Act, for a breach that exposed contact details and the bank details of roughly 3,000 Oyster refund customers. This account reconstructs the phishing entry, the lateral movement, the containment that took status boards and the refund portal offline, the NCSC-NCA response, and the municipal-security lessons that outlasted the headlines.

Continue ReadingTfL 2024: A 17-Year-Old, a Social Engineer’s Approach and Oyster Chaos

SolarWinds Web Help Desk RCE: The Name That Hurts Again

On August 21-22, 2024, SolarWinds shipped 12.8.3 HF1 for Web Help Desk and disclosed CVE-2024-28986 — an unauthenticated Java deserialization flaw rated CVSS 9.8 that delivers pre-auth remote code execution on internet-facing instances. Within days PoC code circulated in exploitation attempts, and on August 26 CISA added it to the Known Exploited Vulnerabilities catalog, making patching mandatory across federal networks. This account covers the bug mechanics, the four-day disclosure-to-KEV sprint, and the uncomfortable optics of a SolarWinds product back in emergency-cycle headlines.

Continue ReadingSolarWinds Web Help Desk RCE: The Name That Hurts Again

The Telegram Arrest and the Encryption Debate of 2024

On August 24, 2024, French authorities arrested Telegram founder Pavel Durov at Le Bourget airport, and two days later charged him with complicity in organized-crime offenses enabled by his platform's refusal to cooperate with legal process — the first time a major encrypted-service executive faced criminal liability for governance choices. Released under judicial supervision within days, Durov's case forced every platform lawyer to reprice jurisdictional arbitrage, moderation staffing, and the meaning of cooperation. This account lays out the charges, the encryption-policy fault lines, and the compliance playbook that followed.

Continue ReadingThe Telegram Arrest and the Encryption Debate of 2024

Windows Downdate: Downgrade Attacks Against the OS Itself

At DEF CON 32 in August 2024, SafeBreach's Alon Leviev unveiled Downdate — a technique that abuses the Windows Modules Installer, TrustedInstaller privileges,and deliberately-eased vbsm manifest permission to silently roll back fully-patched Windows binaries to vulnerable prior versions, re-opening fixed BitLocker bypasses and Hyper-V escapes on current builds. This account explains the downgrade mechanics, the CVE-2024-21430 fix timeline, and why the research redefined patch currency as a security property worth defending.

Continue ReadingWindows Downdate: Downgrade Attacks Against the OS Itself

National Public Data: 2.9B SSN Records for the Price of a Breach

In August 2024, national background-check broker National Public Data confirmed a breach that leaked roughly 2.9 billion rows of personal records — names, addresses, relatives, SSNs — covering plausibly every US adult and parts of the UK and Canada, after a criminal actor first offered the data for sale in April and a third party then dumped 277GB free. This account traces the broker supply chain that assembled the dossier, the class-action lawsuit that forced acknowledgment, and the post-SSN security posture every organization now needs.

Continue ReadingNational Public Data: 2.9B SSN Records for the Price of a Breach

AT&T’s Snowflake Ransom Payment: The $370K Precedent

On July 31, 2024, AT&T confirmed its customer data — including call and text metadata of nearly all subscribers and some SSNs — had been stolen off Snowflake's cloud via compromised service-account credentials, and that it had paid roughly $370,000 to the SQlMap-scanning crew known as ShinyHunters to delete it. This account reconstructs the credential theft, the infostealer-to-Snowflake kill chain, the economics of a mid-six-figure ransom, and the quarterly-burial of accountability between carrier, and its data-warehouse vendor.

Continue ReadingAT&T’s Snowflake Ransom Payment: The $370K Precedent

CrowdStrike Falcon Outage: 8.5M Hosts & Fragile Architecture

On July 19, 2024, a routine sensor configuration update from CrowdStrike passed staged testing and rolled through the Falcon channel to roughly 8.5 million Windows hosts — and crashed them into Blue Screens of Death, grounding flights, halting broadcasters and hospitals in the largest IT outage in history. This account reconstructs the flawed content-deployment pipeline, the Channel File 291 logic that sent the kernel into chaos, the 78-minute Remediation and guidance HHCfollows, the blame theater that followed, and why the incident rewrote every argument about single-vendor concentration risk.

Continue ReadingCrowdStrike Falcon Outage: 8.5M Hosts & Fragile Architecture
>