T-Mobile API Scraping 2023: 37M Accounts, One Credential
A single compromised API credential let an actor scrape ~37 million T-Mobile accounts over six weeks. Machine-identity governance lessons from a repeat offender.
A single compromised API credential let an actor scrape ~37 million T-Mobile accounts over six weeks. Machine-identity governance lessons from a repeat offender.
CVE-2022-42475 was a CVSS 9.8 pre-auth heap overflow in FortiOS SSL-VPN, patched silently then confirmed exploited. Edge memory safety lessons.
Two Exchange zero-days chained SSRF-to-RCE were sold on a forum before Microsoft's November 2022 patch — and mass-exploited in the gap. Assume-the-edge lessons.
A CVSS 9.8 authentication bypass let attackers add their own SSH keys to FortiOS admin accounts via crafted HTTPS requests. Exploited at disclosure.
CVE-2022-36934 gave WhatsApp a CVSS 9.8 integer-overflow RCE that could execute during the video-call ring — before the victim answered. Zero interaction.
Australia's second-largest telco exposed ~9.8M customer records via an API left unauthenticated in production. No zero-day, no phishing — just enumeration.
A patched OAuth endpoint answered one question too honestly: which phone belongs to which handle. The dataset sold for $30k — the class lesson is still with us.
Sixteen days between disclosure and patch. Who exploited Follina in the gap, how fast state and commodity actors moved, and the doctrine it forged.
Exploited in the wild two days before the patch existed. How OGNL injection turned Confluence into June 2022's internet-scale fire drill — and the playbook it left behind.
A protocol handler, a remote template, a signed diagnostic tool — CVE-2022-30190 executed PowerShell from a Word file with macros fully disabled.
A JDK 9 property path reopened a 2010-era bug class in Spring's data binder — and gave every Tomcat admin a very bad 48 hours.
A mod_lua multipart buffer overflow announced ten days after Log4Shell. Narrow exposure, but a masterclass in triage under fatigue.