>

Dependency Confusion: How a Researcher Hacked Apple and Microsoft

No exploits, no stolen credentials — Alex Birsan's February 2021 research got code executed inside 35+ major companies by registering their internal package names on public registries and letting version arithmetic do the rest. The incident file on the cheapest supply-chain attack ever demonstrated.

Continue ReadingDependency Confusion: How a Researcher Hacked Apple and Microsoft

Oldsmar Water Plant Hack: The Five-Minute SCADA Wakeup Call

A remote intruder raised a Florida treatment plant's lye setpoint from 100 to 11,100 ppm and an operator watching the screen reverted it in minutes. The incident file on shared passwords, exposed TeamViewer, and why OT security failed at a municipal water utility.

Continue ReadingOldsmar Water Plant Hack: The Five-Minute SCADA Wakeup Call

Emotet Takedown: How Police Dismantled the World’s Most Dangerous Malware

The incident file on Operation Ladybird: how eight countries dismantled Emotet's 700-server botnet from inside its own update mechanism, why the loader-as-a-service model made Emotet the on-ramp for Ryuk and Conti ransomware, how the brand was rebuilt from TrickBot within ten months, and what the takedown teaches about the ceiling of law-enforcement disruption.

Continue ReadingEmotet Takedown: How Police Dismantled the World’s Most Dangerous Malware

SonicWall SMA Zero-Day: Inside the January 2021 SSL-VPN Campaign

Days after SUNBURST, researchers caught attackers exploiting a 9.8-severity SQL injection in SonicWall SMA 100 appliances — including against SonicWall's own network. This incident file covers how unauthenticated credential extraction turned edge appliances into ransomware on-ramps.

Continue ReadingSonicWall SMA Zero-Day: Inside the January 2021 SSL-VPN Campaign

SolarWinds SUNBURST: Inside the Supply-Chain Attack That Rewrote Security

The full incident file on the SolarWinds SUNBURST supply-chain attack: how SVR-linked actors compromised the Orion build pipeline, trojanized signed updates reaching 18,000 customers, hand-picked under 100 targets including nine US federal agencies, and forged SAML tokens to persist. Includes the technical anatomy, timeline, impact numbers, and the build-pipeline hardening lessons that still define defender programs in 2026.

Continue ReadingSolarWinds SUNBURST: Inside the Supply-Chain Attack That Rewrote Security

Marriott’s Second Breach: 5.2 Million Guest Records Exposed

At the end of March 2020, Marriott disclosed its second major breach in two years: the login credentials of two franchise properties had been abused in late February 2020 to siphon 5.2 million guest records, including names, addresses, phone numbers, birthdays, loyalty details, and in some cases travel itineraries and room preferences. Unlike the 2018 Starwood catastrophe that exposed up to 383 million records, this intrusion was caught and contained within weeks, but it reignited regulatory scrutiny on both sides of the Atlantic. This retrospective covers the intrusion path, the data involved, the disclosure timing, and the aftermath for one of hospitality's biggest names.

Continue ReadingMarriott’s Second Breach: 5.2 Million Guest Records Exposed

When Hackers Hunted the WHO: Cyberattacks in a Pandemic’s First Weeks

On 24 March 2020, Reuters reported that hackers had stood up a near-identical malicious imitation of the World Health Organization's internal email portal, infrastructure aimed at stealing passwords from staffers coordinating the global pandemic response. The same reporting documented that around 450 active WHO email addresses and passwords, plus thousands more belonging to people working on the COVID-19 response, had been leaked online. It was not an isolated incident but part of a documented surge in targeting of health bodies that spring. This piece reconstructs the verified incidents of March 2020 and the wider lesson that crisis response organizations are priority intelligence targets.

Continue ReadingWhen Hackers Hunted the WHO: Cyberattacks in a Pandemic’s First Weeks
>