Follina in the Wild: TA413, Patch Gaps and Zero-Day Economics
Sixteen days between disclosure and patch. Who exploited Follina in the gap, how fast state and commodity actors moved, and the doctrine it forged.
Sixteen days between disclosure and patch. Who exploited Follina in the gap, how fast state and commodity actors moved, and the doctrine it forged.
Exploited in the wild two days before the patch existed. How OGNL injection turned Confluence into June 2022's internet-scale fire drill — and the playbook it left behind.
A protocol handler, a remote template, a signed diagnostic tool — CVE-2022-30190 executed PowerShell from a Word file with macros fully disabled.
Rotating MAC addresses were supposed to make Bluetooth anonymous. May 2022's synthesis of research, stalker hardware, and detection tools proved they never did.
GitHub's OAuth tokens lived in Heroku's infrastructure. One compromised CI cache later, an ecosystem learned where vendor tokens really live.
No stolen keys, no exploit — just a death spiral in the mechanism itself. Why UST's fall is mandatory reading for DeFi threat modelling.
No key stolen, no bug exploited — an attacker borrowed a voting majority on Aave, passed his own proposal, and drained the vaults in one block.
Conti encrypted the treasury during tax season, declared war on the government, and forced the world's first ransomware state of emergency.
Attackers stole GitHub integration tokens from Heroku and Travis CI, pivoted into npm, and downloaded ~109,000 publishing credentials.
A JDK 9 property path reopened a 2010-era bug class in Spring's data binder — and gave every Tomcat admin a very bad 48 hours.
37GB claimed, one account compromised, no customer data lost — and a DEV-0536 profile that taught the industry how social engineering beats MFA.
North Korea's Lazarus Group drained Axie Infinity's Ronin bridge of $625M with five forged signatures and a leftover permission nobody revoked.