Snowflake-Related Arrests: UNC5537’s Kitchener Pinch

On October 30, 2024, Canadian authorities arrested a 26-year-old Kitchener, Ontario man on a US warrant connecting him to the Snowflake-account intrusions tracked by Mandiant as UNC5537 — the crew behind the Ticketmaster, Santander, and AT&T disclosures that dominated 2024’s data-theft calendar. The arrest, first reported in early November by Bloomberg identifying the suspect as Connor Riley Moucka, illuminated the infostealer-credential-to-cloud kill chain and the market for stolen data. This account reconstructs the campaign, the arrest, and the MFA lessons that outlast it.

Continue ReadingSnowflake-Related Arrests: UNC5537’s Kitchener Pinch

Travelex Ransomware 2020: When Sodinokibi Crippled a Currency Giant

On 31 December 2019, foreign exchange giant Travelex took its UK and international websites and mobile apps offline following a cyberattack, an outage that also knocked out white-label travel money services at ASDA, Tesco and Sainsbury’s overnight. When the story became public on 7 January 2020, the criminals behind Sodinokibi (REvil) ransomware were demanding 4.6 million pounds, claiming to have copied more than 5GB of customer data, and the company would spend weeks rebuilding systems by hand. This account reconstructs the verified timeline, the double-extortion playbook, and how the incident contributed to an August 2020 administration that cut more than a thousand UK jobs.

Continue ReadingTravelex Ransomware 2020: When Sodinokibi Crippled a Currency Giant

CurveBall CVE-2020-0601: Forging Trust With One Elliptic Curve Parameter

On 14 January 2020, Microsoft’s first Patch Tuesday of the decade included a fix for CVE-2020-0601, a cryptographic implementation flaw in Windows CryptoAPI reported to the vendor by the U.S. National Security Agency. The bug let anyone forge TLS certificates that appeared to chain to the U.S. government’s ECC trusted root, making malicious HTTPS sites look legitimately signed. Researchers named it CurveBall, proof-of-concept exploits appeared within days, and CISA issued Emergency Directive 20-02 ordering federal agencies to hunt and patch. This is the story of how a single mishandled curve parameter undermined certificate trust Windows-wide.

Continue ReadingCurveBall CVE-2020-0601: Forging Trust With One Elliptic Curve Parameter

Exchange CVE-2020-0688: A Default Key Made Every Server Alike

On 11 February 2020, Microsoft disclosed CVE-2020-0688, a remote code execution vulnerability in Microsoft Exchange Server’s Unified Messaging service that scored 9.8 on CVSS because every installation shipped with the same cryptographic validation key by default. Any authenticated user could send a specially crafted viewstate to the Exchange Control Panel and achieve RCE as SYSTEM, and because service accounts and weak credentials were everywhere, authenticated was a low bar. This analysis walks the vulnerable request path, the viewstate forgery mechanics, the patch, and the long tail of scanning and exploitation that followed for months.

Continue ReadingExchange CVE-2020-0688: A Default Key Made Every Server Alike

Ransomware at a Gas Compression Facility: CISA’s OT Alert

On 20 February 2020, CISA published AA20-030A, a joint advisory describing how ransomware had disrupted a natural gas compression facility: a phishing link let commodity ransomware spread from IT into the OT network, encrypting data historians and polling servers, severing HMI visibility, and leaving operators blind to real-time pressure and flow data for two days. The advisory became a reference model for oil and gas asset owners because it mapped, step by step, how a single email chained into loss of operational visibility without directly controlling pipeline equipment. This retrospective walks through the kill chain, the defensive gaps, and the guidance that followed.

Continue ReadingRansomware at a Gas Compression Facility: CISA’s OT Alert

SMBGhost CVE-2020-0796: Wormable Code in Windows 10 SMBv3

On 11 March 2020, Microsoft shipped a fix for CVE-2020-0796, a wormable remote code execution flaw in how Windows 10 and Windows Server handle compressed SMBv3 packets. An attacker could send a specially crafted compressed packet and trigger a buffer overflow before authentication, exactly the class of bug security people fear could be chained into self-spreading malware. Researchers named it SMBGhost, published proof-of-concepts within days, demonstrated local privilege escalation chains, and Microsoft followed with an out-of-band patch update on 12 March. This technical retrospective covers the flaw mechanics, the compression workaround, the patch wave, and why the wormable nightmare never fully materialized.

Continue ReadingSMBGhost CVE-2020-0796: Wormable Code in Windows 10 SMBv3

When Hackers Hunted the WHO: Cyberattacks in a Pandemic’s First Weeks

On 24 March 2020, Reuters reported that hackers had stood up a near-identical malicious imitation of the World Health Organization’s internal email portal, infrastructure aimed at stealing passwords from staffers coordinating the global pandemic response. The same reporting documented that around 450 active WHO email addresses and passwords, plus thousands more belonging to people working on the COVID-19 response, had been leaked online. It was not an isolated incident but part of a documented surge in targeting of health bodies that spring. This piece reconstructs the verified incidents of March 2020 and the wider lesson that crisis response organizations are priority intelligence targets.

Continue ReadingWhen Hackers Hunted the WHO: Cyberattacks in a Pandemic’s First Weeks

Marriott’s Second Breach: 5.2 Million Guest Records Exposed

At the end of March 2020, Marriott disclosed its second major breach in two years: the login credentials of two franchise properties had been abused in late February 2020 to siphon 5.2 million guest records, including names, addresses, phone numbers, birthdays, loyalty details, and in some cases travel itineraries and room preferences. Unlike the 2018 Starwood catastrophe that exposed up to 383 million records, this intrusion was caught and contained within weeks, but it reignited regulatory scrutiny on both sides of the Atlantic. This retrospective covers the intrusion path, the data involved, the disclosure timing, and the aftermath for one of hospitality’s biggest names.

Continue ReadingMarriott’s Second Breach: 5.2 Million Guest Records Exposed
Read more about the article Phishing Evolution: From Email Scams to AI-Powered Attacks
Phishing Evolution: From Email Scams to AI-Powered Attacks

Phishing Evolution: From Email Scams to AI-Powered Attacks

Trace the evolution of phishing attacks from crude 1990s email scams to AI-powered deepfake campaigns. Discover how attackers leverage machine learning and automation to create convincing social engineering attacks.

Continue ReadingPhishing Evolution: From Email Scams to AI-Powered Attacks
Read more about the article Identity Security: Modern Attacks on Users, Sessions & Trust
Identity Security: Modern Attacks on Users, Sessions & Trust

Identity Security: Modern Attacks on Users, Sessions & Trust

How identity became the new perimeter in modern cybersecurity. Explore MFA bypass techniques, OAuth consent phishing, device code attacks, token theft, and defense strategies for identity-centric security.

Continue ReadingIdentity Security: Modern Attacks on Users, Sessions & Trust

Internet Archive Breach and DDoS: 31M Accounts, One Pop-Up

On October 9, 2024, visitors to the Internet Archive’s Wayback Machine were greeted by an injected JavaScript pop-up announcing the compromise of 31,081,179 user accounts — the HIBP-confirmed count of the organization’s authentication database, loaned from a September exposure of its Zendesk support portal. A concurrent DDoS attributed to SN_BlackMeta compounded the disruption; days later, archived XSS attempts confirmed the org’sJavaScript security debt. This account traces the initial access, the pop-up’s evidence chain, and the funding-and-fragility story of a library built on hope.

Continue ReadingInternet Archive Breach and DDoS: 31M Accounts, One Pop-Up