HiveNightmare: The Two-Line Bug That Leaked Every Local Password Hash
One broken inheritance flag left Windows SAM, SYSTEM, and SECURITY hives readable by any user. With shadow copies in play, that meant every local NTLM hash on the box.
One broken inheritance flag left Windows SAM, SYSTEM, and SECURITY hives readable by any user. With shadow copies in play, that meant every local NTLM hash on the box.
The Pegasus Project exposed 50,000 targeted numbers and a hard truth: modern mercenary spyware infects phones through iMessage and WhatsApp without the victim doing anything.
REvil turned Kaseya's remote-management platform into a mass-encryption weapon, hitting ~60 MSPs and up to 1,500 downstream businesses days before a patch could land.
Tens of thousands of abandoned Western Digital NAS drives got factory-reset by strangers through a decade-old unpatched flaw. The definitive end-of-life IoT case study.
No attack, no breach — a single customer config met a dormant software bug and took Reddit, the Guardian, and roughly a tenth of the internet offline for an hour. The concentration-risk wake-up call.
REvil halted the world's largest meat processor over a holiday weekend; JBS restored from backups — and still paid $11M for leak suppression and restart insurance. The economics of ransom beyond decryption.
DarkSide entered through a no-MFA legacy VPN password, exfiltrated 100 GB, and encrypted Colonial's IT — prompting a precautionary shutdown of 45% of East Coast fuel supply. Anatomy of the most policy-consequential ransomware ever.
A 2019 contact-import scrape of 533M users hit every phone number to profile, free-dumped in 2021 and still fueling vishing and SIM-swaps today. Why data age barely dents attacker value.
A tampered Codecov Bash Uploader quietly shipped CI environment variables — cloud keys, tokens, signing material — to attackers for two months. The curl-pipe-bash trust model dissected, and how build supply-chain security was rewritten after.
By March 2021 REvil paired a record $50M Acer demand with leak-site auctions and affiliate economics — industrialised extortion at its zenith. How the machine worked and why every brand since runs its playbook.
A CVSS 9.8 unauthenticated RCE in BIG-IP iControl REST was mass-exploited within a day of disclosure — web shells, credential theft, coinminers on the boxes that hold your TLS keys. The edge-device patch-race case study.
Teenage hackers turned one exposed Verkada dev server into super-admin access over ~150,000 customer cameras — hospitals, jails, Tesla, Cloudflare. The third-party camera risk case that rewrote vendor security questionnaires.