>

Ray AI Framework’s ‘Won’t Fix’ CVEs: A Control-Plane Debate

When Protect AI disclosed five Ray vulnerabilities in March 2024 — including critical RCE via the unauthenticated control plane — Anyscale's 'won't fix, trusted-networks design' stance ignited the year's sharpest debate over AI infrastructure responsibility. This piece unpacks the job-submission RCE, the exposed-cluster census, the bounty economics, what Anyscale later shipped anyway, and the hardening playbook that became standard for every exposed ML control plane.

Continue ReadingRay AI Framework’s ‘Won’t Fix’ CVEs: A Control-Plane Debate

JetBrains TeamCity Auth Bypass: Build Servers as Front Door

March 2024's CVE-2024-27198 let unauthenticated attackers mint admin accounts on self-hosted TeamCity CI servers, converting every connected build agent into attacker-controlled execution holding source, secrets and signing keys. This piece covers the alternate-path authentication bypass, the companion path traversal, the ransomware crews that queued within days, and the year's hard-learned rule that build infrastructure deserves domain-controller-grade security.

Continue ReadingJetBrains TeamCity Auth Bypass: Build Servers as Front Door

LockBit Takedown: Operation Cronos and Its Awkward Aftermath

February 2024's Operation Cronos seized LockBit's infrastructure across a dozen countries — and then the leaks showed how long the FBI had been inside. This account covers the covert access, the sting timing driven by UK hospital targeting, the servers and affiliate accounts taken down, the hurried rebrand to LockBit 4.1, the affiliate diaspora to RansomHub and Akira, and the awkward questions the takedown's trolling raised about reading crime statistics.

Continue ReadingLockBit Takedown: Operation Cronos and Its Awkward Aftermath

Change Healthcare ALPHV: The Ransomware That Broke US Healthcare

One ALPHV/BlackCat intrusion in February 2024 froze claims and pharmacy payments across US healthcare for weeks — the single most consequential ransomware attack of the year. This account covers the nine-day dwell time, the $22 million ransom payment and the exit-scam double-cross that brought RansomHub back for seconds, the eventual disclosure of hundreds of millions of records, and why one processor's central position converted a single encryptor into a national healthcare liquidity crisis.

Continue ReadingChange Healthcare ALPHV: The Ransomware That Broke US Healthcare

ConnectWise ScreenConnect Auth Bypass: An Instant RCE Wave

February 2024's CVE-2024-1709 let anyone add administrative accounts to self-hosted ScreenConnect servers — a setup-wizard path traversal that converted remote-support consoles into ransomware deployment platforms within 72 hours of disclosure. This account covers the twinned vulnerabilities, why MSP-hosted instances multiplied the blast radius across client fleets, the observed ransomware sequences, and the hard questions RMM vendors faced about unauthenticated wizard endpoints.

Continue ReadingConnectWise ScreenConnect Auth Bypass: An Instant RCE Wave

Wyze Camera Flaw: 13,000 Strangers Through One Caching Hole

Two February 2024 vulnerabilities let Wyze app users briefly see thumbnails and live feeds of strangers' cameras — a cache-key failure amplified by a three-year-old flaw resurfacing in redesigned hardware. This account covers the date-based cache-key bug, the 13,000 affected users, the nine-hour fleet update, and the uncomfortable questions about budget-camera security engineering when the same vendor has now repeated the vulnerability class.

Continue ReadingWyze Camera Flaw: 13,000 Strangers Through One Caching Hole

AnyDesk Breach: Production Compromise and a Certificate Sprint

Remote-access maker AnyDesk confirmed in February 2024 that attackers had compromised production systems using valid credentials traced to infostealer logs — forcing a certificate rotation, password resets, and a rushed 8.1.1 release whose code-signing was intact but whose credibility needed rebuilding. This piece covers the infostealer-to-supply-chain escalation path that rewired vendor-risk thinking, and why remote-admin tooling became a tier-one identity perimeter.

Continue ReadingAnyDesk Breach: Production Compromise and a Certificate Sprint

MOAB: The 26 Billion-Record Compilation That Wasn’t a Breach

The January 2024 'Mother of All Breaches' headline turned out to be a compilation of thousands of prior incidents re-hosted in a misconfigured bucket — 26 billion rows of recycled credentials stacked into a credential-stuffing goldmine. This piece explains why aggregations are not new breaches but still multiply risk, how the 12-terabyte trove mapped to old LinkedIn, Adobe and MyFitnessPal leaks, and why password reuse makes every old breach a live 2024 attack.

Continue ReadingMOAB: The 26 Billion-Record Compilation That Wasn’t a Breach

Midnight Blizzard vs Microsoft: Legacy Tenant to Executive Email

A defunct test tenant, a legacy password without MFA, and a residential-proxy password spray gave Russia's Midnight Blizzard a foothold inside Microsoft's own corporate estate in January 2024 — culminating in stolen executive email and a downstream supplier breach wave. This account explains the password-spray tradecraft, how the actors abused OAuth apps to mine mailboxes, why the failure drew a czar-memo mea culpa, and the SEC disclosure mechanics that made the saga public.

Continue ReadingMidnight Blizzard vs Microsoft: Legacy Tenant to Executive Email

Ivanti Connect Secure Zero-Days: The Edge-Appliance Crisis

January 2024 opened with the year's first appliance crisis: two pre-authentication zero-days in Ivanti Connect Secure that nation-state actors had already exploited, followed by integrity-check failures and a reset wave across thousands of enterprise VPNs. This account covers CVE-2023-46805 and CVE-2024-21887, the mass exploitation between disclosure and patch, the customers whose breaches surfaced weeks later, and why edge appliances became the year's most contested patch surface.

Continue ReadingIvanti Connect Secure Zero-Days: The Edge-Appliance Crisis

Apple’s iOS 17.2 Bluetooth Fixes vs the Flipper Zero Craze

December 2023's patch wave closed the chapter on a strange season: cheap programmable gadgets spraying Bluetooth frames in public, iPhones crashing in viral videos, and Apple shipping denial-of-service fixes in the iOS 17.2 family. This piece explains the crash-pair CVEs, why Bluetooth's design makes every phone an always-on parser for stranger traffic, how the December 20 advisory window anchored the fixes, and why proximity protocols remain a permanent hardening frontier for every device maker.

Continue ReadingApple’s iOS 17.2 Bluetooth Fixes vs the Flipper Zero Craze

SMTP Smuggling: Spoofing Email With Authenticated Mail

December 2023 brought one of email's most elegant attacks: SMTP smuggling, a parser-level desync that tricks receiving servers into writing attacker-authored messages that pass SPF and DMARC because the victim's own infrastructure vouches for them. This deep dive covers the technique mechanics (end-of-data ambiguity, the second hidden MAIL FROM conversation), the December 19 disclosure and DHL demonstration, the two anchoring CVEs, which product families patched, and the durable lessons for mail admins running anything that speaks SMTP.

Continue ReadingSMTP Smuggling: Spoofing Email With Authenticated Mail
>