Skip to content
Hmmnm brand header logo displayed prominently across the top of the webpage
  • Home
  • Blog
  • About Us
  • Contact
  • Services
  • Products
  • Cybersecurity Learning Paths
  • Toggle website search
Press Escape to close the search panel.
Menu Close
  • Home
  • Blog
  • About Us
  • Contact
  • Services
  • Products
  • Cybersecurity Learning Paths
  • Toggle website search
Search this website

Cyberattacks 2021

  1. Home>
  2. Blog>
  3. Cyberattacks 2021
Read more about the article PwnKit: The 12-Year Local Root in Every Linux

PwnKit: The 12-Year Local Root in Every Linux

  • Post author:Prabhu Kalyan Samal
  • Post published:September 5, 2026
  • Post category:Cloud & Infrastructure/Security

CVE-2021-4034 gave instant root on default Linux installs via pure logic flaw. Why setuid code still deserves emergency attention.

Continue ReadingPwnKit: The 12-Year Local Root in Every Linux
Read more about the article Apache httpd CVE-2021-44790: The RCE After Log4Shell

Apache httpd CVE-2021-44790: The RCE After Log4Shell

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security/Web & API Security

A mod_lua multipart buffer overflow announced ten days after Log4Shell. Narrow exposure, but a masterclass in triage under fatigue.

Continue ReadingApache httpd CVE-2021-44790: The RCE After Log4Shell
Read more about the article Log4Shell (CVE-2021-44228): How One Logging Library Broke the Internet

Log4Shell (CVE-2021-44228): How One Logging Library Broke the Internet

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security/Web & API Security

A single JNDI lookup string turned every Java logger into a front door. The anatomy, response, and lasting lessons of Log4Shell.

Continue ReadingLog4Shell (CVE-2021-44228): How One Logging Library Broke the Internet
Read more about the article AWS us-east-1 Outage: When Multi-Region Wasn’t

AWS us-east-1 Outage: When Multi-Region Wasn’t

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security

A DYNOMITE autoscaler impairment cascaded through AWS’s busiest region and its own consoles. The dependency-concentration landmark.

Continue ReadingAWS us-east-1 Outage: When Multi-Region Wasn’t
Read more about the article GoDaddy Breach: One Phished Password, 1.2 Million Sites Exposed

GoDaddy Breach: One Phished Password, 1.2 Million Sites Exposed

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security/Supply Chain Security

Two months of undetected access to managed WordPress hosting, wholesale sFTP and database credential harvesting, and SSL keys in the bargain.

Continue ReadingGoDaddy Breach: One Phished Password, 1.2 Million Sites Exposed
Read more about the article Facebook’s BGP Outage: Six Hours, Self-Inflicted, Total

Facebook’s BGP Outage: Six Hours, Self-Inflicted, Total

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security

One maintenance command withdrew Facebook’s backbone routes, took DNS with it, and locked engineers out of the fix. The outage defended itself.

Continue ReadingFacebook’s BGP Outage: Six Hours, Self-Inflicted, Total
Read more about the article Apache Path Traversal: CVE-2021-41773 Broke in 24 Hours

Apache Path Traversal: CVE-2021-41773 Broke in 24 Hours

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security/Web & API Security

A single encoded GET walked out of Apache’s docroot, and the first patch didn’t hold. Inside the October 2021 traversal zero-day scramble.

Continue ReadingApache Path Traversal: CVE-2021-41773 Broke in 24 Hours
Read more about the article T-Mobile 2021: 76.6 Million Records Through One Unprotected API

T-Mobile 2021: 76.6 Million Records Through One Unprotected API

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security/Web & API Security

No zero-days, no malware — just weak router credentials, a flat network, and an internal API with no authentication. The Binns breach rewrote telecom disclosure playbooks.

Continue ReadingT-Mobile 2021: 76.6 Million Records Through One Unprotected API
Read more about the article HiveNightmare: The Two-Line Bug That Leaked Every Local Password Hash

HiveNightmare: The Two-Line Bug That Leaked Every Local Password Hash

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security

One broken inheritance flag left Windows SAM, SYSTEM, and SECURITY hives readable by any user. With shadow copies in play, that meant every local NTLM hash on the box.

Continue ReadingHiveNightmare: The Two-Line Bug That Leaked Every Local Password Hash
Read more about the article F5 BIG-IP RCE (CVE-2021-22986): The 9.8 Edge Emergency

F5 BIG-IP RCE (CVE-2021-22986): The 9.8 Edge Emergency

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security/Web & API Security

A CVSS 9.8 unauthenticated RCE in BIG-IP iControl REST was mass-exploited within a day of disclosure — web shells, credential theft, coinminers on the boxes that hold your TLS keys. The edge-device patch-race case study.

Continue ReadingF5 BIG-IP RCE (CVE-2021-22986): The 9.8 Edge Emergency
Press Escape to close the search panel.

Categories

  • AI Security (1)
  • Aviation and Aerospace Security (9)
  • Beyond Security (1)
  • Security (339)
  • Technology (62)

Recent Posts

  • Abusing OIDC in CI/CD: A Step-by-Step Tutorial on GitHub Actions Token Trust Chains
  • How to Hash Passwords in 2026: Argon2id, bcrypt and the NIST Baseline
  • Terraform State: The Most Sensitive File in Your Infrastructure
  • Hands-On Container Escape Lab: Privilege Escalation from Pod to Node with Real Commands
  • JWT Security: alg=none, Key Confusion and Why the Header Lies
  • Weekly Threat Intel: Supply Chain Compromises, Autumn CVE Exploitation and Infostealer Trends
  • UEFI Secure Boot and BlackLotus: The Boot Chain of Trust Under Attack
  • Weekly Threat Intel: Edge CVEs, MCP Agent Abuse, Stealer Cashouts
  • HTTP/3 and QUIC: How the Web Moved to a New Transport
  • Dependency Confusion Lab: Reproduce and Defend Your Pipeline
  • Cosign Signing and Verification Lab: Sign, Verify, Enforce
  • Kerberos Attack Paths: Golden Tickets, Silver Tickets and Kerberoasting
  • DNSSEC Explained: Chain of Trust, NSEC3 and the October 2026 Root Rollover
  • BOLA and Broken Auth API Attacks with Burp Suite: Lab Guide
  • OWASP ZAP DAST Lab: Authenticated API Scanning Explained

Archives

  • September 2026 (260)
  • August 2026 (98)

Newsletter

Get all latest content delivered to your email a few times a month. Updates and news about all categories will send to you.
Email is required Email is not valid
This field is required
Thanks for your subscription.
Failed to subscribe, please contact admin.
Hmmnm

Our Other Sites

  • Hmmnm.in
  • Odia.hmmnm.in

Quick Links

  • Security Services
  • Learning Paths
  • About Us
  • Contact
  • Blog
  • Privacy Policy
  • Disclaimer
  • Security Products
  • Terms of Service

Contact Info

  • 📧 contact@hmmnm.com
  • 🌐 hmmnm.com
in
© 2026 @Hmmnm

We use cookies to understand how the site is used and to improve your experience. You can accept analytics cookies or continue with essential cookies only. Privacy Policy

  • Home
  • Blog
  • Security
  • Experience
  • About Us
  • Services
  • Contact