Follina: The Office Zero-Day That Needed No Macros
A protocol handler, a remote template, a signed diagnostic tool — CVE-2022-30190 executed PowerShell from a Word file with macros fully disabled.
A protocol handler, a remote template, a signed diagnostic tool — CVE-2022-30190 executed PowerShell from a Word file with macros fully disabled.
Exploited in the wild two days before the patch existed. How OGNL injection turned Confluence into June 2022’s internet-scale fire drill — and the playbook it left behind.
A JDK 9 property path reopened a 2010-era bug class in Spring’s data binder — and gave every Tomcat admin a very bad 48 hours.
A mod_lua multipart buffer overflow announced ten days after Log4Shell. Narrow exposure, but a masterclass in triage under fatigue.
A single JNDI lookup string turned every Java logger into a front door. The anatomy, response, and lasting lessons of Log4Shell.
A single encoded GET walked out of Apache’s docroot, and the first patch didn’t hold. Inside the October 2021 traversal zero-day scramble.
No zero-days, no malware — just weak router credentials, a flat network, and an internal API with no authentication. The Binns breach rewrote telecom disclosure playbooks.
Three patched-but-unapplied Exchange bugs chained into unauthenticated RCE. Webshells, mailbox theft, and ransomware followed at population scale within two weeks.
Pre-auth Pulse Secure exploits handed APT crews and ransomware affiliates appliance-level control of the VPNs that carried pandemic remote work. How credential capture and patch-surviving persistence rewrote edge-appliance incident response.
A CVSS 9.8 unauthenticated RCE in BIG-IP iControl REST was mass-exploited within a day of disclosure — web shells, credential theft, coinminers on the boxes that hold your TLS keys. The edge-device patch-race case study.
Four zero-days in on-premises Microsoft Exchange let HAFNIUM and ten follow-on crews own mail servers at tens of thousands of organisations. The anatomy of the SSRF-to-web-shell chain, the PATCH NOW scramble, and why patching was not remediation.