Crypto.com’s $34M Lesson: The 2FA Bypass Blueprint
Attackers defeated the second factor, not the vault, draining $34M from 483 accounts before a platform-wide withdrawal halt stopped them.
Attackers defeated the second factor, not the vault, draining $34M from 483 accounts before a platform-wide withdrawal halt stopped them.
Attackers abused a misconfigured FBI notification system to spam fake cyber-warnings from the real fbi.gov address, exposing the limits of email trust.
The SolarWinds actor returned with no implant at all — sprayed passwords, replayed tokens, and delegated partner admin rights over 609 channel companies.
No zero-days, no malware — just weak router credentials, a flat network, and an internal API with no authentication. The Binns breach rewrote telecom disclosure playbooks.
PetitPotam coerced Windows machines to authenticate, AD CS web enrollment happily minted a DC certificate, and domains fell in an afternoon. The relay class is still with us.
The Pegasus Project exposed 50,000 targeted numbers and a hard truth: modern mercenary spyware infects phones through iMessage and WhatsApp without the victim doing anything.
AirTags made competent covert tracking cost $29 and zero skill. From pre launch warnings to prosecutions and the Apple-Google alert spec, the full history of a safety-by-design failure — and the platform fixes that finally landed.
ATT turned iOS advertising identifiers opt-in overnight, denial rates hit 80%+, and Meta booked a $10B impact. How one consent dialog restructured an ad economy — and pushed tracking into fingerprinting’s arms.
Teenage hackers turned one exposed Verkada dev server into super-admin access over ~150,000 customer cameras — hospitals, jails, Tesla, Cloudflare. The third-party camera risk case that rewrote vendor security questionnaires.
Passkeys went mainstream in 2026. Learn how phishing-resistant passwordless authentication works and the 4 new attacks targeting recovery flows and sessions.
Zero Trust for AI systems requires rethinking identity, data flows, and access control. Learn the five pillars of AI Zero Trust — identity verification, input validation, least privilege, monitoring, and encryption — with practical architecture patterns and implementation roadmap.