Medibank 2022: The Ransom Refusal That Published Patients
Criminals entered Medibank via a contractor's VPN credentials on a gateway without MFA, then dumped 9.7M customers' health data after the ransom refusal.
Criminals entered Medibank via a contractor's VPN credentials on a gateway without MFA, then dumped 9.7M customers' health data after the ransom refusal.
CVE-2022-42889 in Apache Commons Text scored CVSS 9.8 but needed apps to interpolate attacker strings — most never did. The reachability-triage lesson.
A CVSS 9.8 authentication bypass let attackers add their own SSH keys to FortiOS admin accounts via crafted HTTPS requests. Exploited at disclosure.
CVE-2022-36934 gave WhatsApp a CVSS 9.8 integer-overflow RCE that could execute during the video-call ring — before the victim answered. Zero interaction.
A Lapsus$-linked teenager allegedly reached Rockstar's Slack via helpdesk social engineering and posted 90+ GTA VI dev clips. The collaboration suite was the vault.
Australia's second-largest telco exposed ~9.8M customer records via an API left unauthenticated in production. No zero-day, no phishing — just enumeration.
An 18-year-old bought a contractor's Uber password, bombarded them with MFA pushes until one was approved, then roamed to vSphere via hardcoded credentials.
August's 'contained' developer-account compromise returned in December as stolen vault backups. Inside the two-act breach.
A forums database with bcrypt hashes and salts hit a criminal forum. The real blast radius was everywhere else users reused passwords.
Slope's telemetry backend held plaintext seed phrases, and attackers harvested them. The chain saw only valid signatures — and that is the whole lesson.
Fake Okta pages, real-time MFA relay, and one crew harvesting 10,000 identities. Why Cloudflare walked away clean and Twilio didn't.
A routine upgrade left message proofs rubber-stamped. Hundreds of copycats drained the bridge in crypto's most chaotic heist.
New threat analyses, tool guides and hardening playbooks — delivered straight to your inbox, the moment they go live.