>
Read more about the article Software Supply Chain Security: Risks in Dependencies, Builds, and Secrets
Supply Chain Security: Risks in Dependencies, Builds & Secrets

Software Supply Chain Security: Risks in Dependencies, Builds, and Secrets

A practical guide to software supply chain security covering dependency risks, secrets exposure, CI/CD trust failures, artifact integrity verification, SBOM management, and real-world attack case studies.

Continue ReadingSoftware Supply Chain Security: Risks in Dependencies, Builds, and Secrets

Snowflake-Related Arrests: UNC5537’s Kitchener Pinch

On October 30, 2024, Canadian authorities arrested a 26-year-old Kitchener, Ontario man on a US warrant connecting him to the Snowflake-account intrusions tracked by Mandiant as UNC5537 — the crew behind the Ticketmaster, Santander, and AT&T disclosures that dominated 2024's data-theft calendar. The arrest, first reported in early November by Bloomberg identifying the suspect as Connor Riley Moucka, illuminated the infostealer-credential-to-cloud kill chain and the market for stolen data. This account reconstructs the campaign, the arrest, and the MFA lessons that outlast it.

Continue ReadingSnowflake-Related Arrests: UNC5537’s Kitchener Pinch

Internet Archive Breach and DDoS: 31M Accounts, One Pop-Up

On October 9, 2024, visitors to the Internet Archive's Wayback Machine were greeted by an injected JavaScript pop-up announcing the compromise of 31,081,179 user accounts — the HIBP-confirmed count of the organization's authentication database, loaned from a September exposure of its Zendesk support portal. A concurrent DDoS attributed to SN_BlackMeta compounded the disruption; days later, archived XSS attempts confirmed the org'sJavaScript security debt. This account traces the initial access, the pop-up's evidence chain, and the funding-and-fragility story of a library built on hope.

Continue ReadingInternet Archive Breach and DDoS: 31M Accounts, One Pop-Up

TfL 2024: A 17-Year-Old, a Social Engineer’s Approach and Oyster Chaos

On September 5, 2024, Transport for London detected an intrusion begun days earlier through social engineering of staff — and within a week a 17-year-old was arrested, then charged under the Computer Misuse Act, for a breach that exposed contact details and the bank details of roughly 3,000 Oyster refund customers. This account reconstructs the phishing entry, the lateral movement, the containment that took status boards and the refund portal offline, the NCSC-NCA response, and the municipal-security lessons that outlasted the headlines.

Continue ReadingTfL 2024: A 17-Year-Old, a Social Engineer’s Approach and Oyster Chaos

Windows Downdate: Downgrade Attacks Against the OS Itself

At DEF CON 32 in August 2024, SafeBreach's Alon Leviev unveiled Downdate — a technique that abuses the Windows Modules Installer, TrustedInstaller privileges,and deliberately-eased vbsm manifest permission to silently roll back fully-patched Windows binaries to vulnerable prior versions, re-opening fixed BitLocker bypasses and Hyper-V escapes on current builds. This account explains the downgrade mechanics, the CVE-2024-21430 fix timeline, and why the research redefined patch currency as a security property worth defending.

Continue ReadingWindows Downdate: Downgrade Attacks Against the OS Itself

National Public Data: 2.9B SSN Records for the Price of a Breach

In August 2024, national background-check broker National Public Data confirmed a breach that leaked roughly 2.9 billion rows of personal records — names, addresses, relatives, SSNs — covering plausibly every US adult and parts of the UK and Canada, after a criminal actor first offered the data for sale in April and a third party then dumped 277GB free. This account traces the broker supply chain that assembled the dossier, the class-action lawsuit that forced acknowledgment, and the post-SSN security posture every organization now needs.

Continue ReadingNational Public Data: 2.9B SSN Records for the Price of a Breach

CrowdStrike Falcon Outage: 8.5M Hosts & Fragile Architecture

On July 19, 2024, a routine sensor configuration update from CrowdStrike passed staged testing and rolled through the Falcon channel to roughly 8.5 million Windows hosts — and crashed them into Blue Screens of Death, grounding flights, halting broadcasters and hospitals in the largest IT outage in history. This account reconstructs the flawed content-deployment pipeline, the Channel File 291 logic that sent the kernel into chaos, the 78-minute Remediation and guidance HHCfollows, the blame theater that followed, and why the incident rewrote every argument about single-vendor concentration risk.

Continue ReadingCrowdStrike Falcon Outage: 8.5M Hosts & Fragile Architecture

Squarespace Domain Hijackings: The 2024 GoDaddy Migration Aftermath

After Squarespace absorbed roughly 10 million domains from Google Domains in mid-2024, attackers discovered a seam: legacy Google-account login flows stopped being enforced, and formerly eNom-transferred .dev/.us domains could be taken over by re-registering then-unlinked accounts. From late June through July, crypto-draining hijacks of high-value domains — including Matomo founder trust abusing Squarespace lock states — left registry operators and site owners scrambling. This account traces the migration mechanics, the attack window, and the DNS tenure lessons.

Continue ReadingSquarespace Domain Hijackings: The 2024 GoDaddy Migration Aftermath
>