>

AnyDesk Breach: Production Compromise and a Certificate Sprint

Remote-access maker AnyDesk confirmed in February 2024 that attackers had compromised production systems using valid credentials traced to infostealer logs — forcing a certificate rotation, password resets, and a rushed 8.1.1 release whose code-signing was intact but whose credibility needed rebuilding. This piece covers the infostealer-to-supply-chain escalation path that rewired vendor-risk thinking, and why remote-admin tooling became a tier-one identity perimeter.

Continue ReadingAnyDesk Breach: Production Compromise and a Certificate Sprint

MOAB: The 26 Billion-Record Compilation That Wasn’t a Breach

The January 2024 'Mother of All Breaches' headline turned out to be a compilation of thousands of prior incidents re-hosted in a misconfigured bucket — 26 billion rows of recycled credentials stacked into a credential-stuffing goldmine. This piece explains why aggregations are not new breaches but still multiply risk, how the 12-terabyte trove mapped to old LinkedIn, Adobe and MyFitnessPal leaks, and why password reuse makes every old breach a live 2024 attack.

Continue ReadingMOAB: The 26 Billion-Record Compilation That Wasn’t a Breach

Midnight Blizzard vs Microsoft: Legacy Tenant to Executive Email

A defunct test tenant, a legacy password without MFA, and a residential-proxy password spray gave Russia's Midnight Blizzard a foothold inside Microsoft's own corporate estate in January 2024 — culminating in stolen executive email and a downstream supplier breach wave. This account explains the password-spray tradecraft, how the actors abused OAuth apps to mine mailboxes, why the failure drew a czar-memo mea culpa, and the SEC disclosure mechanics that made the saga public.

Continue ReadingMidnight Blizzard vs Microsoft: Legacy Tenant to Executive Email

Mr. Cooper Mortgage Breach: The Week Payments Stopped

When one of America's largest mortgage servicers went dark for a week, the harm went far beyond stolen data. The Mr. Cooper incident — detected October 24, disclosed October 31, 2023 — halted payments, escrow, and payoffs for millions of borrowers, and later filings put the notification count near 14.7 million people with Social Security numbers and bank account details in the mix. This account covers the stolen-credential entry, the outage that regulators treated as the real injury, the mortgage-sector dependencies that amplified it, and the durable lessons for any payment-critical firm.

Continue ReadingMr. Cooper Mortgage Breach: The Week Payments Stopped

DP World Australia: When a Cyber Incident Stopped the Cranes

On 13 November 2023, DP World Australia disconnected its port systems from the internet to contain an intrusion — and container operations at Sydney, Melbourne, Brisbane and Fremantle stopped cold, stranding roughly 30,000 containers for three days. Operations resumed by 16 November, personnel data exposure was later confirmed, and no ransom payment was disclosed. The episode became Australia's reference case for cyber-driven supply-chain disruption and a model of disciplined containment, rapid restoration and honest capacity communication under SOI-Act scrutiny.

Continue ReadingDP World Australia: When a Cyber Incident Stopped the Cranes

ChatGPT’s November 2023 DDoS Outages, Explained

For much of 8 November 2023, ChatGPT and parts of OpenAI's API cycled in and out of service under a denial-of-service wave claimed by Anonymous Sudan, with smaller recurrences through the month. OpenAI confirmed the DDoS, rolled global WAF rules, and absorbed a false-positive tax on legitimate users. Nothing was breached — the story is availability risk wrapped around AI dependence. This post walks the campaign's anatomy, Microsoft's Storm-1359 telemetry link, and the business-continuity lessons for anyone running on AI vendors.

Continue ReadingChatGPT’s November 2023 DDoS Outages, Explained

LockBit, CitrixBleed, and the ICBC Treasury Hack

When LockBit hit ICBC's US broker-dealer on 9 November 2023, Treasury-market connectivity went dark and manual settlement took over for days. The entry path traced to CitrixBleed session tokens stolen before the October patch and never invalidated — exactly what CISA's Emergency Directive 23-08 had warned. LockBit claimed a roughly $9 million ransom demand, never verified. The post walks the token-replay kill chain, the disclosure-era aftermath, and the defensive lesson that remediation includes revocation.

Continue ReadingLockBit, CitrixBleed, and the ICBC Treasury Hack

23andMe Credential Stuffing: When Relatives Are the Payload

Reused passwords took over 14,000 23andMe accounts, then the DNA Relatives feature amplified the access into profile data for 6.9 million genetically-linked users. The October 2023 breach rewrote breach math: your exposure now includes every relative's password hygiene.

Continue Reading23andMe Credential Stuffing: When Relatives Are the Payload

MGM, Caesars, and Scattered Spider: The Vishing Fall of 2023

In September 2023 Scattered Spider vished the MGM helpdesk, pivoted through Okta to ESXi, and detonated ALPHV ransomware — a $100M quarter for MGM while Caesars paid up. The reference incident for helpdesk verification, MFA fatigue, and pay-vs-rebuild economics.

Continue ReadingMGM, Caesars, and Scattered Spider: The Vishing Fall of 2023
>