Reddit’s Phishing Breach: When MFA Codes Get Phished Too
A cloned intranet page harvested an employee's password and MFA code, opening hours of internal access. Phishing-resistant MFA and self-report lessons.
A cloned intranet page harvested an employee's password and MFA code, opening hours of internal access. Phishing-resistant MFA and self-report lessons.
GoDaddy's 2023 filing admitted intermittent intruder access since 2020, malware in cPanel servers, and email interception affecting ~6.95M customers.
ESXiArgs hit thousands of unpatched VMware ESXi hosts via old OpenSLP bugs in February 2023. Hypervisor ransomware and recovery-script lessons.
A single compromised API credential let an actor scrape ~37 million T-Mobile accounts over six weeks. Machine-identity governance lessons from a repeat offender.
LockBit encrypted Royal Mail's international sorting operations in January 2023 and demanded $80M. Royal Mail paid nothing and kept the letters moving.
LastPass confirmed attackers copied encrypted vault backups after pivoting through a DevOps engineer's endpoint. KDF legacy and unencrypted metadata set the real risk.
Ransomware forced the Guardian's newsroom off its networks for weeks in late 2022 — yet print and web kept publishing. Editorial continuity lessons.
USDoD hijacked a chapter president's InfraGard account and listed 87,000 members' PII for sale. Identity lessons for trusted-community portals.
Rackspace's December 2022 ransomware incident took Hosted Exchange down for weeks, ended the product's life, and cost $12M+. Legacy platform lessons.
CVE-2022-42475 was a CVSS 9.8 pre-auth heap overflow in FortiOS SSL-VPN, patched silently then confirmed exploited. Edge memory safety lessons.
Two Exchange zero-days chained SSRF-to-RCE were sold on a forum before Microsoft's November 2022 patch — and mass-exploited in the gap. Assume-the-edge lessons.
An attacker forged a bridge proof to mint 2M BNB (~$570M), then validators halted the chain mid-launder. Only ~$100M escaped before the freeze.