SMTP Smuggling: Spoofing Email With Authenticated Mail

December 2023 brought one of email's most elegant attacks: SMTP smuggling, a parser-level desync that tricks receiving servers into writing attacker-authored messages that pass SPF and DMARC because the victim's own infrastructure vouches for them. This deep dive covers the technique mechanics (end-of-data ambiguity, the second hidden MAIL FROM conversation), the December 19 disclosure and DHL demonstration, the two anchoring CVEs, which product families patched, and the durable lessons for mail admins running anything that speaks SMTP.

Continue ReadingSMTP Smuggling: Spoofing Email With Authenticated Mail

LockBit, CitrixBleed, and the ICBC Treasury Hack

When LockBit hit ICBC's US broker-dealer on 9 November 2023, Treasury-market connectivity went dark and manual settlement took over for days. The entry path traced to CitrixBleed session tokens stolen before the October patch and never invalidated — exactly what CISA's Emergency Directive 23-08 had warned. LockBit claimed a roughly $9 million ransom demand, never verified. The post walks the token-replay kill chain, the disclosure-era aftermath, and the defensive lesson that remediation includes revocation.

Continue ReadingLockBit, CitrixBleed, and the ICBC Treasury Hack

F5 BIG-IP Request Smuggling 2023: The 9.8 Desync

CVE-2023-46747 let unauthenticated attackers smuggle requests through BIG-IP TMM into the iControl REST management plane — a framing bug that became full device compromise. Exploitation followed the October patch within days, and CISA put it on the KEV catalog before month end.

Continue ReadingF5 BIG-IP Request Smuggling 2023: The 9.8 Desync

Cisco BroadWorks CVE-2023-20237: The SSO Bypass Scare

In September 2023 Cisco rushed out patches for CVE-2023-20237, a critical authentication bypass in BroadWorks' single-sign-on flows that could let attackers authenticate as any user. With evidence of active scanning, carrier admins ran an emergency patch marathon.

Continue ReadingCisco BroadWorks CVE-2023-20237: The SSO Bypass Scare