>

APT29 Inside TeamViewer: 2024’s Calmest, Most Instructive Breach

On June 28, 2024, TeamViewer disclosed that a state-sponsored actor — widely reported as Russia's APT29 — had breached its corporate IT network through a standard employee's credentials, and that the remote-access product itself, and every customer, stayed untouched. This account reconstructs the hours-to-containment timeline, explains why corporate/product segmentation carried the day, places the intrusion in Cozy Bear's patient espionage season, and draws the anti-SolarWinds comparison that made this 2024's most instructive breach.

Continue ReadingAPT29 Inside TeamViewer: 2024’s Calmest, Most Instructive Breach

Polyfill.io Hijack: 100,000+ Sites Inherited a Malicious Script

When Sansec disclosed in late June 2024 that the polyfill.io domain had been sold and its hosted script rewritten to inject mobile-only scam redirects, hundreds of thousands of embedded sites — WordPress themes among them — discovered they had inherited an implant, invisible to desktop QA by design. This account traces the Funnull acquisition chain, the conditional payload mechanics, Cloudflare's mirror intervention, the DNS-harassment retaliation, the 2025 arrests, and the inventory lesson every site owner still owes themselves.

Continue ReadingPolyfill.io Hijack: 100,000+ Sites Inherited a Malicious Script

Brain Cipher vs Indonesia’s Data Centers: A National Ransomware Reckoning

In June 2024, the Brain Cipher crew — running a LockBit 3.0 builder clone — encrypted Indonesia's National Data Center, disrupting 200+ government services from immigration to licensing, then released a decryptor with an apology-flavored admission that extortion failed, then hit again during recovery. This account covers the copycat-crew economics behind the operation, why one shared-tenant data center meant national outage, the second-encryption lesson about persistence, and the segmented-architecture rebuild Indonesia promised next.

Continue ReadingBrain Cipher vs Indonesia’s Data Centers: A National Ransomware Reckoning

CDK Global Ransomware: US Car Dealerships Run on Pen and Paper

On June 19, 2024, ransomware hit CDK Global's dealer management platform — the operational nervous system of ~15,000 North American dealerships — and a second strike during recovery extended the outage for weeks while finance desks, service bays and OEM ordering reverted to paper and fax. This account covers the June 19/22 double-hit timeline, the billion-dollar industry loss estimates, why DMS lock-in made fallback manual rather than competitive, and the concentration-risk docket the incident left for every regulator to cite.

Continue ReadingCDK Global Ransomware: US Car Dealerships Run on Pen and Paper

Snowflake Extortion: 165+ Customers, One Credential Wave

On June 19, 2024, Mandiant's public advisory named UNC5537 as the crew behind the Snowflake extortion wave — 165+ victim organizations entered with infostealer credentials against MFA-less tenants, datasets extorted through listings and a dedicated leak market researchers dubbed Snow:Bay. This piece condenses the TTP catalogue, the backyard economics of stolen logs, the aftermarket that changed notification obligations forever, and the single control that would have prevented every confirmed intrusion.

Continue ReadingSnowflake Extortion: 165+ Customers, One Credential Wave

Snowflake-Ticketmaster: The Cloud-Secure Myth Breaks

Live Nation's May 2024 SEC filing confirmed criminal access to roughly 560 million Ticketmaster customer records — taken not by exploiting Snowflake but by logging into it with infostealer-derived credentials on a tenant without MFA. This account explains the UNC5537 tradecraft that chained $20 stealer logs into Fortune-500 data lakes, why the 'no Snowflake breach' defense only half-worked, what the ~560M-record dataset contained, and the mandatory-MFA wave that reshaped SaaS identity through 2024.

Continue ReadingSnowflake-Ticketmaster: The Cloud-Secure Myth Breaks

Sisense Breach: CI Credentials, AWS Keys and a CISA Advisory

On April 24, 2024, CISA and the FBI advised every Sisense customer to rotate credentials after attackers compromised the BI vendor's development environment — and by week's end, Sisense-issued AWS keys were circulating publicly. This piece reconstructs the five-day arc from detection to contained, explains why business-intelligence platforms are credential funnels that turn vendor CI/CD breaches into customer incidents, and extracts the third-party-risk doctrine the episode left behind for every embedded-analytics supply chain.

Continue ReadingSisense Breach: CI Credentials, AWS Keys and a CISA Advisory

PuTTY ECDSA Nonce Bias: How 71 Signatures Exposed Your SSH Key

PuTTY's April 2024 advisory for CVE-2024-31497 read like a physics problem: the terminal's ECDSA implementation biased nonces on NIST P-521, so roughly 71 captured SSH signatures suffice for a lattice attack that recovers the private key. This piece explains the Hidden Number Problem math, why archived PCAP and DLP session capture retroactively weaponized years of traffic, the 0.81 deterministic-nonce fix, and the brutal rotation drill that made every P-521 key used through Pageant presumptively burned.

Continue ReadingPuTTY ECDSA Nonce Bias: How 71 Signatures Exposed Your SSH Key

AT&T 73M Leak: The 2019 Dataset That Resurfaced Free

March 2024's 73-million-record AT&T leak was an old wound reopened: a 2019-era vendor-workspace dataset, shopped unsuccessfully in 2021, finally dumped free on a hacking forum with SSNs and account details intact. This account disentangles it from the concurrent Snowflake campaign, explains why free publication maximizes criminal utility, maps the 7.6 million passcode resets, and follows the extortion thread that later surfaced in DOJ filings.

Continue ReadingAT&T 73M Leak: The 2019 Dataset That Resurfaced Free

The XZ Utils Backdoor: Inside the Almost-Catastrophe

The most patient supply-chain attack ever caught — a two-year maintainer infiltration that planted an SSH backdoor into xz-utils release tarballs, discovered in March 2024 only because one engineer noticed 500 milliseconds of latency. This account traces the Jia Tan persona from helpful contributor to release engineer, the test-file obfuscation and build-stage injection, the systemd/sshd target chain, the near-miss that kept stable distros clean, and the trust-model reforms that rippled through open source.

Continue ReadingThe XZ Utils Backdoor: Inside the Almost-Catastrophe

LockBit Takedown: Operation Cronos and Its Awkward Aftermath

February 2024's Operation Cronos seized LockBit's infrastructure across a dozen countries — and then the leaks showed how long the FBI had been inside. This account covers the covert access, the sting timing driven by UK hospital targeting, the servers and affiliate accounts taken down, the hurried rebrand to LockBit 4.1, the affiliate diaspora to RansomHub and Akira, and the awkward questions the takedown's trolling raised about reading crime statistics.

Continue ReadingLockBit Takedown: Operation Cronos and Its Awkward Aftermath

Change Healthcare ALPHV: The Ransomware That Broke US Healthcare

One ALPHV/BlackCat intrusion in February 2024 froze claims and pharmacy payments across US healthcare for weeks — the single most consequential ransomware attack of the year. This account covers the nine-day dwell time, the $22 million ransom payment and the exit-scam double-cross that brought RansomHub back for seconds, the eventual disclosure of hundreds of millions of records, and why one processor's central position converted a single encryptor into a national healthcare liquidity crisis.

Continue ReadingChange Healthcare ALPHV: The Ransomware That Broke US Healthcare
>