Skip to content
Hmmnm brand header logo displayed prominently across the top of the webpage
  • Home
  • Blog
  • About Us
  • Contact
  • Toggle website search
Press Escape to close the search panel.
Menu Close
  • Home
  • Blog
  • About Us
  • Contact
  • Toggle website search
Search this website

Cloud & Infrastructure

  1. Home>
  2. Blog>
  3. Security>
  4. Cloud & Infrastructure>
  5. Page 7
Read more about the article AWS us-east-1 Outage: When Multi-Region Wasn’t

AWS us-east-1 Outage: When Multi-Region Wasn’t

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security

A DYNOMITE autoscaler impairment cascaded through AWS’s busiest region and its own consoles. The dependency-concentration landmark.

Continue ReadingAWS us-east-1 Outage: When Multi-Region Wasn’t
Read more about the article GoDaddy Breach: One Phished Password, 1.2 Million Sites Exposed

GoDaddy Breach: One Phished Password, 1.2 Million Sites Exposed

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security/Supply Chain Security

Two months of undetected access to managed WordPress hosting, wholesale sFTP and database credential harvesting, and SSL keys in the bargain.

Continue ReadingGoDaddy Breach: One Phished Password, 1.2 Million Sites Exposed
Read more about the article Facebook’s BGP Outage: Six Hours, Self-Inflicted, Total

Facebook’s BGP Outage: Six Hours, Self-Inflicted, Total

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security

One maintenance command withdrew Facebook’s backbone routes, took DNS with it, and locked engineers out of the fix. The outage defended itself.

Continue ReadingFacebook’s BGP Outage: Six Hours, Self-Inflicted, Total
Read more about the article Apache Path Traversal: CVE-2021-41773 Broke in 24 Hours

Apache Path Traversal: CVE-2021-41773 Broke in 24 Hours

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security/Web & API Security

A single encoded GET walked out of Apache’s docroot, and the first patch didn’t hold. Inside the October 2021 traversal zero-day scramble.

Continue ReadingApache Path Traversal: CVE-2021-41773 Broke in 24 Hours
Read more about the article OMIGOD: The Root Bug Hiding in Azure’s Invisible Linux Agent

OMIGOD: The Root Bug Hiding in Azure’s Invisible Linux Agent

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security

A malformed request header turned OMI into root-level remote code execution on millions of Azure Linux VMs. Most owners never knew the agent existed.

Continue ReadingOMIGOD: The Root Bug Hiding in Azure’s Invisible Linux Agent
Read more about the article ChaosDB: The Azure Cosmos DB Chain That Crossed Tenants

ChaosDB: The Azure Cosmos DB Chain That Crossed Tenants

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security

A notebook container bug, an embedded certificate, and a confused gateway let any Cosmos DB customer read every other tenant’s data. Fixed in 48 hours, taught forever.

Continue ReadingChaosDB: The Azure Cosmos DB Chain That Crossed Tenants
Read more about the article ProxyShell: The August 2021 Exchange Pillage After Hafnium

ProxyShell: The August 2021 Exchange Pillage After Hafnium

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security/Web & API Security

Three patched-but-unapplied Exchange bugs chained into unauthenticated RCE. Webshells, mailbox theft, and ransomware followed at population scale within two weeks.

Continue ReadingProxyShell: The August 2021 Exchange Pillage After Hafnium
Read more about the article PetitPotam and ESC8: The NTLM Relay Chain That Owned Active Directory

PetitPotam and ESC8: The NTLM Relay Chain That Owned Active Directory

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Identity & Phishing/Security

PetitPotam coerced Windows machines to authenticate, AD CS web enrollment happily minted a DC certificate, and domains fell in an afternoon. The relay class is still with us.

Continue ReadingPetitPotam and ESC8: The NTLM Relay Chain That Owned Active Directory
Read more about the article HiveNightmare: The Two-Line Bug That Leaked Every Local Password Hash

HiveNightmare: The Two-Line Bug That Leaked Every Local Password Hash

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security

One broken inheritance flag left Windows SAM, SYSTEM, and SECURITY hives readable by any user. With shadow copies in play, that meant every local NTLM hash on the box.

Continue ReadingHiveNightmare: The Two-Line Bug That Leaked Every Local Password Hash
Read more about the article PrintNightmare: When the Patch Didn’t Fix Anything

PrintNightmare: When the Patch Didn’t Fix Anything

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security

A leaked PoC, a patch that didn’t patch, and weeks of registry-hardening confusion — how CVE-2021-34527 turned Windows Print Spooler into a domain-takeover primitive.

Continue ReadingPrintNightmare: When the Patch Didn’t Fix Anything
Read more about the article Fastly CDN Outage 2021: One Config, 10% of the Web Down

Fastly CDN Outage 2021: One Config, 10% of the Web Down

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security

No attack, no breach — a single customer config met a dormant software bug and took Reddit, the Guardian, and roughly a tenth of the internet offline for an hour. The concentration-risk wake-up call.

Continue ReadingFastly CDN Outage 2021: One Config, 10% of the Web Down
Read more about the article Biden’s Zero Trust Executive Order: The Procurement Pivot

Biden’s Zero Trust Executive Order: The Procurement Pivot

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Emerging Tech & Architecture/Security

EO 14028 turned zero trust from slide-ware into federal procurement doctrine — MFA, SBOMs, NIST 800-207, the Cyber Safety Review Board — and reset vendor incentives industry-wide.

Continue ReadingBiden’s Zero Trust Executive Order: The Procurement Pivot
  • Go to the previous page
  • 1
  • …
  • 4
  • 5
  • 6
  • 7
  • 8
  • Go to the next page
Press Escape to close the search panel.

Categories

  • AI Security (1)
  • Aviation and Aerospace Security (9)
  • Beyond Security (2)
  • Security (357)
  • Technology (63)

Recent Posts

  • Alert Fatigue Is a Design Problem: Building a Detection Engineering Lifecycle That Survives Contact
  • Write Sigma Rules That Actually Fire: A Detection-as-Code Lab with SigmaCLI and splunk-react
  • Why Planes Don’t Get Hacked — And Where the Next Aviation Cyber Risk Really Is
  • What Is Prompt Injection and How to Prevent It: A Complete Exam Prep Guide
  • Pyramid of Pain to Production: How Detection Engineers Prioritize What to Hunt
  • Build a Free Elastic Security SOC: Ingest Sysmon, Create Dashboards and Triage Alerts
  • Testing JWT Security with jwt-cli and Caido: Alg Confusion, Weak Secrets, and Expired Claims
  • Weekly Threat Intel: 30 September 2026 — npm Malware, Typosquat Waves and Autumn CVEs
  • Evilginx3 Lab: Build a Safe AiTM Phishing Lab to Understand Session Cookie Theft (and Why FIDO2 Stops It)
  • MFA Fatigue and Push Bombing: How Attackers Wear Down Your Users
  • Shodan and Censys for Attack Surface Recon: A Hands-On OSINT Lab with Ethics Guardrails
  • Weekly Threat Intel: 27 September 2026 — Agentic Supply Chain Abuse and CVE Trades
  • Abusing GraphQL Introspection and Batching: A Hands-On API Attack Lab with Defenses
  • SQLite Runs the World: Inside the Most Deployed Database Ever
  • SSRF Lab: Exploit and Block Server-Side Request Forgery with Real Targets and Defenses

Archives

  • October 2026 (8)
  • September 2026 (272)
  • August 2026 (98)

Newsletter

Get all latest content delivered to your email a few times a month. Updates and news about all categories will send to you.
Email is required Email is not valid
This field is required
Thanks for your subscription.
Failed to subscribe, please contact admin.
Hmmnm

Our Other Sites

  • Hmmnm.in
  • Odia.hmmnm.in

Quick Links

  • Security Services
  • Learning Paths
  • About Us
  • Contact
  • Blog
  • Privacy Policy
  • Disclaimer
  • Security Products
  • Terms of Service

Contact Info

  • 📧 contact@hmmnm.com
  • 🌐 hmmnm.com
in
© 2026 @Hmmnm

We use cookies to understand how the site is used and to improve your experience. You can accept analytics cookies or continue with essential cookies only. Privacy Policy

  • Home
  • Blog
  • Security
  • Experience
  • About Us
  • Services
  • Contact