Colonial Pipeline Ransomware: One Password, 17 Emergency States

DarkSide entered through a no-MFA legacy VPN password, exfiltrated 100 GB, and encrypted Colonial’s IT — prompting a precautionary shutdown of 45% of East Coast fuel supply. Anatomy of the most policy-consequential ransomware ever.

Continue ReadingColonial Pipeline Ransomware: One Password, 17 Emergency States

CD Projekt Red Ransomware: The Source-Code Auction That Failed

HelloKitty ransomware encrypted CDPR’s network and stole Cyberpunk 2077 and Witcher 3 source code — then auctioned it on a crime forum after the studio refused to pay. The incident file on IP extortion, auction economics, and the no-ransom playbook.

Continue ReadingCD Projekt Red Ransomware: The Source-Code Auction That Failed

Emotet Takedown: How Police Dismantled the World’s Most Dangerous Malware

The incident file on Operation Ladybird: how eight countries dismantled Emotet’s 700-server botnet from inside its own update mechanism, why the loader-as-a-service model made Emotet the on-ramp for Ryuk and Conti ransomware, how the brand was rebuilt from TrickBot within ten months, and what the takedown teaches about the ceiling of law-enforcement disruption.

Continue ReadingEmotet Takedown: How Police Dismantled the World’s Most Dangerous Malware
Read more about the article AST01: Malicious Agent Skills (ClawHavoc Case Study)
OWASP Agentic Skills Top 10 series cover (cover_p2.png)

AST01: Malicious Agent Skills (ClawHavoc Case Study)

AST01 of the OWASP Agentic Skills Top 10 dissected: how ClawHavoc shipped 1,184 malicious skills from 12 accounts, why five of ClawHub's top seven downloads were malware, and how three lines of markdown exfiltrated SSH keys - with the full attack playbook and controls.

Continue ReadingAST01: Malicious Agent Skills (ClawHavoc Case Study)
Read more about the article No Malware Needed: How Attackers Turn Your Own Admin Tools Against You
Living off the land signed toolshed

No Malware Needed: How Attackers Turn Your Own Admin Tools Against You

PowerShell, WMI, scheduled tasks, certutil: signed by the OS vendor, whitelisted by AV, trusted by EDR. Living-off-the-land attacks drop no malware, so detection cannot hinge on unknown binaries. The shift from artifact blacklists to execution-baseline analytics that actually catches native-tool chains.

Continue ReadingNo Malware Needed: How Attackers Turn Your Own Admin Tools Against You