PwnKit: The 12-Year Local Root in Every Linux
CVE-2021-4034 gave instant root on default Linux installs via pure logic flaw. Why setuid code still deserves emergency attention.
CVE-2021-4034 gave instant root on default Linux installs via pure logic flaw. Why setuid code still deserves emergency attention.
No zero-days, no malware — just MFA fatigue, SIM swaps, and help-desk social engineering. How Lapsus$ broke every assumption.
Attackers defeated the second factor, not the vault, draining $34M from 483 accounts before a platform-wide withdrawal halt stopped them.
A mod_lua multipart buffer overflow announced ten days after Log4Shell. Narrow exposure, but a masterclass in triage under fatigue.
UKG's Kronos Private Cloud ransomware outage forced thousands of employers onto paper time cards. The definitive SaaS continuity case.
A single JNDI lookup string turned every Java logger into a front door. The anatomy, response, and lasting lessons of Log4Shell.
A DYNOMITE autoscaler impairment cascaded through AWS's busiest region and its own consoles. The dependency-concentration landmark.
Ten months after its takedown, Emotet returned via a TrickBot module. The lesson: criminal franchises rebuild through partners.
Attackers abused a misconfigured FBI notification system to spam fake cyber-warnings from the real fbi.gov address, exposing the limits of email trust.
Two months of undetected access to managed WordPress hosting, wholesale sFTP and database credential harvesting, and SSL keys in the bargain.
Popular packages with dormant maintainers pushed info-stealers through postinstall scripts. The registry was fine; the accounts were not.
The SolarWinds actor returned with no implant at all — sprayed passwords, replayed tokens, and delegated partner admin rights over 609 channel companies.
New threat analyses, tool guides and hardening playbooks — delivered straight to your inbox, the moment they go live.