Ray AI Framework’s ‘Won’t Fix’ CVEs: A Control-Plane Debate

When Protect AI disclosed five Ray vulnerabilities in March 2024 — including critical RCE via the unauthenticated control plane — Anyscale’s ‘won’t fix, trusted-networks design’ stance ignited the year’s sharpest debate over AI infrastructure responsibility. This piece unpacks the job-submission RCE, the exposed-cluster census, the bounty economics, what Anyscale later shipped anyway, and the hardening playbook that became standard for every exposed ML control plane.

Continue ReadingRay AI Framework’s ‘Won’t Fix’ CVEs: A Control-Plane Debate

Sisense Breach: CI Credentials, AWS Keys and a CISA Advisory

On April 24, 2024, CISA and the FBI advised every Sisense customer to rotate credentials after attackers compromised the BI vendor’s development environment — and by week’s end, Sisense-issued AWS keys were circulating publicly. This piece reconstructs the five-day arc from detection to contained, explains why business-intelligence platforms are credential funnels that turn vendor CI/CD breaches into customer incidents, and extracts the third-party-risk doctrine the episode left behind for every embedded-analytics supply chain.

Continue ReadingSisense Breach: CI Credentials, AWS Keys and a CISA Advisory

BGP Hijacking’s 2023 Resurgence, and What RPKI Fixed

All through 2023, route leaks and suspected BGP hijacks kept redirecting chunks of internet traffic — events touching Rostelecom-linked infrastructure, financial services, and a persistent streak of cryptocurrency-targeting interception paths. None matched the famed mass redirections of prior years, but the pattern of brief, deniable, hard-to-attribute incidents kept routing security in the research headlines. This year-end review explains how BGP trust fails, walks the 2023 incident ledger with appropriately hedged attribution, and covers the defensive state of the art: RPKI signing crossing majority coverage, MANRS norms, and external route monitoring.

Continue ReadingBGP Hijacking’s 2023 Resurgence, and What RPKI Fixed

MGM, Caesars, and Scattered Spider: The Vishing Fall of 2023

In September 2023 Scattered Spider vished the MGM helpdesk, pivoted through Okta to ESXi, and detonated ALPHV ransomware — a $100M quarter for MGM while Caesars paid up. The reference incident for helpdesk verification, MFA fatigue, and pay-vs-rebuild economics.

Continue ReadingMGM, Caesars, and Scattered Spider: The Vishing Fall of 2023

Cisco BroadWorks CVE-2023-20237: The SSO Bypass Scare

In September 2023 Cisco rushed out patches for CVE-2023-20237, a critical authentication bypass in BroadWorks’ single-sign-on flows that could let attackers authenticate as any user. With evidence of active scanning, carrier admins ran an emergency patch marathon.

Continue ReadingCisco BroadWorks CVE-2023-20237: The SSO Bypass Scare

Storm-0558 Forged-Token Breach: The Stolen Key That Read Government Email

China-linked Storm-0558 forged Azure AD tokens with a stolen Microsoft consumer signing key and read email at ~25 organizations including the State and Commerce departments — exposing vendor key hygiene, token scope validation, and log-tiering as board-level security questions.

Continue ReadingStorm-0558 Forged-Token Breach: The Stolen Key That Read Government Email