>

Midnight Blizzard vs Microsoft: Legacy Tenant to Executive Email

A defunct test tenant, a legacy password without MFA, and a residential-proxy password spray gave Russia's Midnight Blizzard a foothold inside Microsoft's own corporate estate in January 2024 — culminating in stolen executive email and a downstream supplier breach wave. This account explains the password-spray tradecraft, how the actors abused OAuth apps to mine mailboxes, why the failure drew a czar-memo mea culpa, and the SEC disclosure mechanics that made the saga public.

Continue ReadingMidnight Blizzard vs Microsoft: Legacy Tenant to Executive Email

Ivanti Connect Secure Zero-Days: The Edge-Appliance Crisis

January 2024 opened with the year's first appliance crisis: two pre-authentication zero-days in Ivanti Connect Secure that nation-state actors had already exploited, followed by integrity-check failures and a reset wave across thousands of enterprise VPNs. This account covers CVE-2023-46805 and CVE-2024-21887, the mass exploitation between disclosure and patch, the customers whose breaches surfaced weeks later, and why edge appliances became the year's most contested patch surface.

Continue ReadingIvanti Connect Secure Zero-Days: The Edge-Appliance Crisis

Apple’s iOS 17.2 Bluetooth Fixes vs the Flipper Zero Craze

December 2023's patch wave closed the chapter on a strange season: cheap programmable gadgets spraying Bluetooth frames in public, iPhones crashing in viral videos, and Apple shipping denial-of-service fixes in the iOS 17.2 family. This piece explains the crash-pair CVEs, why Bluetooth's design makes every phone an always-on parser for stranger traffic, how the December 20 advisory window anchored the fixes, and why proximity protocols remain a permanent hardening frontier for every device maker.

Continue ReadingApple’s iOS 17.2 Bluetooth Fixes vs the Flipper Zero Craze

SMTP Smuggling: Spoofing Email With Authenticated Mail

December 2023 brought one of email's most elegant attacks: SMTP smuggling, a parser-level desync that tricks receiving servers into writing attacker-authored messages that pass SPF and DMARC because the victim's own infrastructure vouches for them. This deep dive covers the technique mechanics (end-of-data ambiguity, the second hidden MAIL FROM conversation), the December 19 disclosure and DHL demonstration, the two anchoring CVEs, which product families patched, and the durable lessons for mail admins running anything that speaks SMTP.

Continue ReadingSMTP Smuggling: Spoofing Email With Authenticated Mail

Mr. Cooper Mortgage Breach: The Week Payments Stopped

When one of America's largest mortgage servicers went dark for a week, the harm went far beyond stolen data. The Mr. Cooper incident — detected October 24, disclosed October 31, 2023 — halted payments, escrow, and payoffs for millions of borrowers, and later filings put the notification count near 14.7 million people with Social Security numbers and bank account details in the mix. This account covers the stolen-credential entry, the outage that regulators treated as the real injury, the mortgage-sector dependencies that amplified it, and the durable lessons for any payment-critical firm.

Continue ReadingMr. Cooper Mortgage Breach: The Week Payments Stopped

BGP Hijacking’s 2023 Resurgence, and What RPKI Fixed

All through 2023, route leaks and suspected BGP hijacks kept redirecting chunks of internet traffic — events touching Rostelecom-linked infrastructure, financial services, and a persistent streak of cryptocurrency-targeting interception paths. None matched the famed mass redirections of prior years, but the pattern of brief, deniable, hard-to-attribute incidents kept routing security in the research headlines. This year-end review explains how BGP trust fails, walks the 2023 incident ledger with appropriately hedged attribution, and covers the defensive state of the art: RPKI signing crossing majority coverage, MANRS norms, and external route monitoring.

Continue ReadingBGP Hijacking’s 2023 Resurgence, and What RPKI Fixed

DP World Australia: When a Cyber Incident Stopped the Cranes

On 13 November 2023, DP World Australia disconnected its port systems from the internet to contain an intrusion — and container operations at Sydney, Melbourne, Brisbane and Fremantle stopped cold, stranding roughly 30,000 containers for three days. Operations resumed by 16 November, personnel data exposure was later confirmed, and no ransom payment was disclosed. The episode became Australia's reference case for cyber-driven supply-chain disruption and a model of disciplined containment, rapid restoration and honest capacity communication under SOI-Act scrutiny.

Continue ReadingDP World Australia: When a Cyber Incident Stopped the Cranes

ChatGPT’s November 2023 DDoS Outages, Explained

For much of 8 November 2023, ChatGPT and parts of OpenAI's API cycled in and out of service under a denial-of-service wave claimed by Anonymous Sudan, with smaller recurrences through the month. OpenAI confirmed the DDoS, rolled global WAF rules, and absorbed a false-positive tax on legitimate users. Nothing was breached — the story is availability risk wrapped around AI dependence. This post walks the campaign's anatomy, Microsoft's Storm-1359 telemetry link, and the business-continuity lessons for anyone running on AI vendors.

Continue ReadingChatGPT’s November 2023 DDoS Outages, Explained

LockBit, CitrixBleed, and the ICBC Treasury Hack

When LockBit hit ICBC's US broker-dealer on 9 November 2023, Treasury-market connectivity went dark and manual settlement took over for days. The entry path traced to CitrixBleed session tokens stolen before the October patch and never invalidated — exactly what CISA's Emergency Directive 23-08 had warned. LockBit claimed a roughly $9 million ransom demand, never verified. The post walks the token-replay kill chain, the disclosure-era aftermath, and the defensive lesson that remediation includes revocation.

Continue ReadingLockBit, CitrixBleed, and the ICBC Treasury Hack

23andMe Credential Stuffing: When Relatives Are the Payload

Reused passwords took over 14,000 23andMe accounts, then the DNA Relatives feature amplified the access into profile data for 6.9 million genetically-linked users. The October 2023 breach rewrote breach math: your exposure now includes every relative's password hygiene.

Continue Reading23andMe Credential Stuffing: When Relatives Are the Payload

Okta Support Breach 2023: Session Tokens Beat MFA Again

Attackers compromised an Okta support engineer's personal device, stole the session cookies inside it, and used Okta's own support console against a customer base estimated at five percent of tenants. BeyondTrust, 1Password, and Cloudflare each detected the downstream activity independently — before the full scope was confirmed.

Continue ReadingOkta Support Breach 2023: Session Tokens Beat MFA Again
>