Twitch Leak: 125GB of Source Code and Payouts on 4chan
No malware, no zero-day — one exposed internal endpoint handed over Twitch's entire codebase and three years of creator earnings.
No malware, no zero-day — one exposed internal endpoint handed over Twitch's entire codebase and three years of creator earnings.
One maintenance command withdrew Facebook's backbone routes, took DNS with it, and locked engineers out of the fix. The outage defended itself.
A single encoded GET walked out of Apache's docroot, and the first patch didn't hold. Inside the October 2021 traversal zero-day scramble.
October 2021's FSB operation ended REvil with arrests, asset seizures, and infrastructure capture. The talent lived on elsewhere.
Five years of notice, one expired root, and a clever cross-sign that kept old Android trusting Let's Encrypt. The rehearsal for every future trust migration.
A malformed request header turned OMI into root-level remote code execution on millions of Azure Linux VMs. Most owners never knew the agent existed.
A notebook container bug, an embedded certificate, and a confused gateway let any Cosmos DB customer read every other tenant's data. Fixed in 48 hours, taught forever.
A forged keeper-list substitution drained $611M across three chains. Then the attacker gave it all back. The bridge bug class that defined Web3's worst year.
No zero-days, no malware — just weak router credentials, a flat network, and an internal API with no authentication. The Binns breach rewrote telecom disclosure playbooks.
Three patched-but-unapplied Exchange bugs chained into unauthenticated RCE. Webshells, mailbox theft, and ransomware followed at population scale within two weeks.
PetitPotam coerced Windows machines to authenticate, AD CS web enrollment happily minted a DC certificate, and domains fell in an afternoon. The relay class is still with us.
New threat analyses, tool guides and hardening playbooks — delivered straight to your inbox, the moment they go live.