Snowflake-Related Arrests: UNC5537’s Kitchener Pinch

On October 30, 2024, Canadian authorities arrested a 26-year-old Kitchener, Ontario man on a US warrant connecting him to the Snowflake-account intrusions tracked by Mandiant as UNC5537 — the crew behind the Ticketmaster, Santander, and AT&T disclosures that dominated 2024’s data-theft calendar. The arrest, first reported in early November by Bloomberg identifying the suspect as Connor Riley Moucka, illuminated the infostealer-credential-to-cloud kill chain and the market for stolen data. This account reconstructs the campaign, the arrest, and the MFA lessons that outlast it.

Continue ReadingSnowflake-Related Arrests: UNC5537’s Kitchener Pinch

After Soleimani: The January 2020 US-Iran Cyber Alert Wave

Within hours of the 3 January 2020 strike that killed Iranian general Qasem Soleimani, security agencies on both sides of the Atlantic braced for cyber retaliation. On 6 January 2020 a U.S. federal website, the Federal Depository Library Program, was defaced with pro-Iran messaging and an image of a bloodied President Trump, claimed by a group calling itself Iran Silk Hat, while CISA and the FBI renewed warnings about possible Iranian attacks on critical infrastructure. This retrospective maps the verified incidents of that week, separates hype from evidence, and explains why agencies treated the moment as a genuine escalation trigger despite limited actual damage.

Continue ReadingAfter Soleimani: The January 2020 US-Iran Cyber Alert Wave

Clearview AI in 2020: Three Billion Scraped Faces, One Leaked Client List

In late February 2020, facial recognition startup Clearview AI confirmed that a misconfigured server had exposed its entire client list, days after a major newspaper investigation revealed the company had scraped more than three billion facial images from social networks and the open web to sell face search to police. The leaked list showed U.S. retailers, banks, and investors among users of a tool built on photos most people never knowingly gave. Cease-and-desist letters from Facebook and other platforms followed, along with GDPR complaints across Europe. This is how facial recognition’s most aggressive company lost control of its own story in a matter of weeks.

Continue ReadingClearview AI in 2020: Three Billion Scraped Faces, One Leaked Client List

Virgin Media 2020: 900,000 People in an Unsecured Marketing Database

On 28 February 2020, Virgin Media confirmed that a marketing database containing the personal details of around 900,000 people had been left insecure and accessible online, discovered not by criminals but by a researcher during unrelated work. The dataset, stored on an unsecured cloud instance, included names, home and email addresses, and phone numbers, and had been reachable for at least ten months. This post explains exactly what was exposed, how the misconfiguration happened, how Virgin Media responded, and what happened next: a textbook non-hack data breach that still required full disclosure, notification, and regulatory scrutiny.

Continue ReadingVirgin Media 2020: 900,000 People in an Unsecured Marketing Database

When Hackers Hunted the WHO: Cyberattacks in a Pandemic’s First Weeks

On 24 March 2020, Reuters reported that hackers had stood up a near-identical malicious imitation of the World Health Organization’s internal email portal, infrastructure aimed at stealing passwords from staffers coordinating the global pandemic response. The same reporting documented that around 450 active WHO email addresses and passwords, plus thousands more belonging to people working on the COVID-19 response, had been leaked online. It was not an isolated incident but part of a documented surge in targeting of health bodies that spring. This piece reconstructs the verified incidents of March 2020 and the wider lesson that crisis response organizations are priority intelligence targets.

Continue ReadingWhen Hackers Hunted the WHO: Cyberattacks in a Pandemic’s First Weeks

Marriott’s Second Breach: 5.2 Million Guest Records Exposed

At the end of March 2020, Marriott disclosed its second major breach in two years: the login credentials of two franchise properties had been abused in late February 2020 to siphon 5.2 million guest records, including names, addresses, phone numbers, birthdays, loyalty details, and in some cases travel itineraries and room preferences. Unlike the 2018 Starwood catastrophe that exposed up to 383 million records, this intrusion was caught and contained within weeks, but it reignited regulatory scrutiny on both sides of the Atlantic. This retrospective covers the intrusion path, the data involved, the disclosure timing, and the aftermath for one of hospitality’s biggest names.

Continue ReadingMarriott’s Second Breach: 5.2 Million Guest Records Exposed

The FBI’s COVID-19 Warning: IC3 and the Scam Surge of March 2020

On 20 March 2020, the FBI’s Internet Crime Complaint Center published a public service announcement warning that cyber criminals were exploiting the COVID-19 pandemic at scale: phishing lures referencing stimulus payments and fake cures, malicious apps, and infrastructure spoofing health authorities. It was one node in a broader wave of official guidance that spring, with CISA and the UK’s NCSC issuing joint advice on pandemic-era remote work and video conferencing security, and IC3’s later reporting would show complaint volumes surging through 2020. This retrospective explains what the warning said, what the threat landscape actually looked like that spring, and how a global crisis became an attack-surface multiplier.

Continue ReadingThe FBI’s COVID-19 Warning: IC3 and the Scam Surge of March 2020
Read more about the article Phishing Evolution: From Email Scams to AI-Powered Attacks
Phishing Evolution: From Email Scams to AI-Powered Attacks

Phishing Evolution: From Email Scams to AI-Powered Attacks

Trace the evolution of phishing attacks from crude 1990s email scams to AI-powered deepfake campaigns. Discover how attackers leverage machine learning and automation to create convincing social engineering attacks.

Continue ReadingPhishing Evolution: From Email Scams to AI-Powered Attacks
Read more about the article Identity Security: Modern Attacks on Users, Sessions & Trust
Identity Security: Modern Attacks on Users, Sessions & Trust

Identity Security: Modern Attacks on Users, Sessions & Trust

How identity became the new perimeter in modern cybersecurity. Explore MFA bypass techniques, OAuth consent phishing, device code attacks, token theft, and defense strategies for identity-centric security.

Continue ReadingIdentity Security: Modern Attacks on Users, Sessions & Trust

Internet Archive Breach and DDoS: 31M Accounts, One Pop-Up

On October 9, 2024, visitors to the Internet Archive’s Wayback Machine were greeted by an injected JavaScript pop-up announcing the compromise of 31,081,179 user accounts — the HIBP-confirmed count of the organization’s authentication database, loaned from a September exposure of its Zendesk support portal. A concurrent DDoS attributed to SN_BlackMeta compounded the disruption; days later, archived XSS attempts confirmed the org’sJavaScript security debt. This account traces the initial access, the pop-up’s evidence chain, and the funding-and-fragility story of a library built on hope.

Continue ReadingInternet Archive Breach and DDoS: 31M Accounts, One Pop-Up

Marriott’s FTC Settlement: 20 Years of Audits for Starwood’s Ghosts

On October 9, 2024, the FTC announced a pair of consent orders — Marriott and its Starwood subsidiary — resolving claims that skimped security contributed to the 2014-2018 Starwood intrusions and a 2018 breach affecting over 131 million consumers from which attackers extracted 5.25 million unencrypted passport numbers. The order imposes 20 years of independent assessments and a claims program offering $150 cash orotomy spending on security — close kin to the UK ICO’s £18.4M fine and the states’ $52M settlement. This account traces the 2014→2018 intrusion, the regulatory pile-on, and what a two-decade oversight tail teaches about inherited security debt.

Continue ReadingMarriott’s FTC Settlement: 20 Years of Audits for Starwood’s Ghosts

Cisco SSM On-Prem Flaws: CVSS 10.0 and a CLI Zero-Day in One Week

In early October 2024, Cisco’s disclosure cadence stacked two unrelated but equally urgent problems: CVE-2024-20419, a CVSS 10.0 unauthenticated password-change flaw in Smart Software Manager On-Prem that let anyone with network access reset the admin API account, and CVE-2024-20399, a CLI command-injection bug in NX-OS already being exploited in the wild per the CISA KEV catalog. This account reconstructs both flaws’ mechanics, the patch timelines, and what this pairing says about authentication surface area in management tooling.

Continue ReadingCisco SSM On-Prem Flaws: CVSS 10.0 and a CLI Zero-Day in One Week