Log4Shell (CVE-2021-44228): How One Logging Library
A single JNDI lookup string turned every Java logger into a front door. The anatomy, response, and lasting lessons of Log4Shell.
A single JNDI lookup string turned every Java logger into a front door. The anatomy, response, and lasting lessons of Log4Shell.
A single encoded GET walked out of Apache's docroot, and the first patch didn't hold. Inside the October 2021 traversal zero-day scramble.
No zero-days, no malware — just weak router credentials, a flat network, and an internal API with no authentication. The Binns breach rewrote telecom disclosure playbooks.
Three patched-but-unapplied Exchange bugs chained into unauthenticated RCE. Webshells, mailbox theft, and ransomware followed at population scale within two weeks.
Pre-auth Pulse Secure exploits handed APT crews and ransomware affiliates appliance-level control of the VPNs that carried pandemic remote work. How credential capture and patch-surviving persistence rewrote edge-appliance incident response.
A CVSS 9.8 unauthenticated RCE in BIG-IP iControl REST was mass-exploited within a day of disclosure — web shells, credential theft, coinminers on the boxes that hold your TLS keys. The edge-device patch-race case study.
Four zero-days in on-premises Microsoft Exchange let HAFNIUM and ten follow-on crews own mail servers at tens of thousands of organisations. The anatomy of the SSRF-to-web-shell chain, the PATCH NOW scramble, and why patching was not remediation.
Google's February 2021 emergency Chrome patch opened a record zero-day year. This incident file breaks down how the V8 heap overflow worked, how it chained with a sandbox escape, why watering-hole delivery leaves no trace, and what fleet-level browser defenses it forced.
Days after SUNBURST, researchers caught attackers exploiting a 9.8-severity SQL injection in SonicWall SMA 100 appliances — including against SonicWall's own network. This incident file covers how unauthenticated credential extraction turned edge appliances into ransomware on-ramps.
On 11 February 2020, Microsoft disclosed CVE-2020-0688, a remote code execution vulnerability in Microsoft Exchange Server's Unified Messaging service that scored 9.8 on CVSS because every installation shipped with the same cryptographic validation key by default. Any authenticated user could send a specially crafted viewstate to the Exchange Control Panel and achieve RCE as SYSTEM, and because service accounts and weak credentials were everywhere, authenticated was a low bar. This analysis walks the vulnerable request path, the viewstate forgery mechanics, the patch, and the long tail of scanning and exploitation that followed for months.
On 17 January 2020, Microsoft published ADV200001, a rare out-of-band advisory for CVE-2020-0674, a remote code execution flaw in the scripting engine used by Internet Explorer 9 and 11 that the company confirmed was being exploited in limited targeted attacks. There was no patch yet, only mitigations and workarounds, and defenders spent nearly a month exposed until the 11 February 2020 cumulative update shipped the fix. This piece reconstructs the advisory, the memory-corruption mechanics in the script engine, why IE was still a live attack surface in 2020, and what the episode taught about mitigations-first disclosure.