National Public Data: 2.9B SSN Records for the Price of a Breach

In August 2024, national background-check broker National Public Data confirmed a breach that leaked roughly 2.9 billion rows of personal records — names, addresses, relatives, SSNs — covering plausibly every US adult and parts of the UK and Canada, after a criminal actor first offered the data for sale in April and a third party then dumped 277GB free. This account traces the broker supply chain that assembled the dossier, the class-action lawsuit that forced acknowledgment, and the post-SSN security posture every organization now needs.

Continue ReadingNational Public Data: 2.9B SSN Records for the Price of a Breach

APT29 Inside TeamViewer: 2024’s Calmest, Most Instructive Breach

On June 28, 2024, TeamViewer disclosed that a state-sponsored actor — widely reported as Russia’s APT29 — had breached its corporate IT network through a standard employee’s credentials, and that the remote-access product itself, and every customer, stayed untouched. This account reconstructs the hours-to-containment timeline, explains why corporate/product segmentation carried the day, places the intrusion in Cozy Bear’s patient espionage season, and draws the anti-SolarWinds comparison that made this 2024’s most instructive breach.

Continue ReadingAPT29 Inside TeamViewer: 2024’s Calmest, Most Instructive Breach

Snowflake Extortion: 165+ Customers, One Credential Wave

On June 19, 2024, Mandiant’s public advisory named UNC5537 as the crew behind the Snowflake extortion wave — 165+ victim organizations entered with infostealer credentials against MFA-less tenants, datasets extorted through listings and a dedicated leak market researchers dubbed Snow:Bay. This piece condenses the TTP catalogue, the backyard economics of stolen logs, the aftermarket that changed notification obligations forever, and the single control that would have prevented every confirmed intrusion.

Continue ReadingSnowflake Extortion: 165+ Customers, One Credential Wave

Snowflake-Ticketmaster: The Cloud-Secure Myth Breaks

Live Nation’s May 2024 SEC filing confirmed criminal access to roughly 560 million Ticketmaster customer records — taken not by exploiting Snowflake but by logging into it with infostealer-derived credentials on a tenant without MFA. This account explains the UNC5537 tradecraft that chained $20 stealer logs into Fortune-500 data lakes, why the ‘no Snowflake breach’ defense only half-worked, what the ~560M-record dataset contained, and the mandatory-MFA wave that reshaped SaaS identity through 2024.

Continue ReadingSnowflake-Ticketmaster: The Cloud-Secure Myth Breaks

Windows Recall: The Privacy Debate Before Launch

Announced May 20, 2024 as a Copilot+ flagship, Windows Recall promised searchable memory of everything on screen — and researchers found the archive in a plaintext SQLite database any user-context malware could read, with a runtime API to match. This account covers Kevin Beaumont’s teardown, the TotalRecall extraction tool, the threat-model fallacies in each Microsoft defense, the June climb-down to opt-in plus Windows Hello and encryption, and the rare process win of an architecture changed before deployment.

Continue ReadingWindows Recall: The Privacy Debate Before Launch

AT&T 73M Leak: The 2019 Dataset That Resurfaced Free

March 2024’s 73-million-record AT&T leak was an old wound reopened: a 2019-era vendor-workspace dataset, shopped unsuccessfully in 2021, finally dumped free on a hacking forum with SSNs and account details intact. This account disentangles it from the concurrent Snowflake campaign, explains why free publication maximizes criminal utility, maps the 7.6 million passcode resets, and follows the extortion thread that later surfaced in DOJ filings.

Continue ReadingAT&T 73M Leak: The 2019 Dataset That Resurfaced Free

Wyze Camera Flaw: 13,000 Strangers Through One Caching Hole

Two February 2024 vulnerabilities let Wyze app users briefly see thumbnails and live feeds of strangers’ cameras — a cache-key failure amplified by a three-year-old flaw resurfacing in redesigned hardware. This account covers the date-based cache-key bug, the 13,000 affected users, the nine-hour fleet update, and the uncomfortable questions about budget-camera security engineering when the same vendor has now repeated the vulnerability class.

Continue ReadingWyze Camera Flaw: 13,000 Strangers Through One Caching Hole

AnyDesk Breach: Production Compromise and a Certificate Sprint

Remote-access maker AnyDesk confirmed in February 2024 that attackers had compromised production systems using valid credentials traced to infostealer logs — forcing a certificate rotation, password resets, and a rushed 8.1.1 release whose code-signing was intact but whose credibility needed rebuilding. This piece covers the infostealer-to-supply-chain escalation path that rewired vendor-risk thinking, and why remote-admin tooling became a tier-one identity perimeter.

Continue ReadingAnyDesk Breach: Production Compromise and a Certificate Sprint

MOAB: The 26 Billion-Record Compilation That Wasn’t a Breach

The January 2024 ‘Mother of All Breaches’ headline turned out to be a compilation of thousands of prior incidents re-hosted in a misconfigured bucket — 26 billion rows of recycled credentials stacked into a credential-stuffing goldmine. This piece explains why aggregations are not new breaches but still multiply risk, how the 12-terabyte trove mapped to old LinkedIn, Adobe and MyFitnessPal leaks, and why password reuse makes every old breach a live 2024 attack.

Continue ReadingMOAB: The 26 Billion-Record Compilation That Wasn’t a Breach

Apple’s iOS 17.2 Bluetooth Fixes vs the Flipper Zero Craze

December 2023’s patch wave closed the chapter on a strange season: cheap programmable gadgets spraying Bluetooth frames in public, iPhones crashing in viral videos, and Apple shipping denial-of-service fixes in the iOS 17.2 family. This piece explains the crash-pair CVEs, why Bluetooth’s design makes every phone an always-on parser for stranger traffic, how the December 20 advisory window anchored the fixes, and why proximity protocols remain a permanent hardening frontier for every device maker.

Continue ReadingApple’s iOS 17.2 Bluetooth Fixes vs the Flipper Zero Craze