Skip to content
Hmmnm brand header logo displayed prominently across the top of the webpage
  • Home
  • Blog
  • About Us
  • Contact
  • Services
  • Products
  • Cybersecurity Learning Paths
  • Toggle website search
Press Escape to close the search panel.
Menu Close
  • Home
  • Blog
  • About Us
  • Contact
  • Services
  • Products
  • Cybersecurity Learning Paths
  • Toggle website search
Search this website

data breach

  1. Home>
  2. Blog>
  3. data breach>
  4. Page 10
Read more about the article npm Hijacking Wave: coa, rc, node-ipc and Stolen Maintainers

npm Hijacking Wave: coa, rc, node-ipc and Stolen Maintainers

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Security/Supply Chain Security

Popular packages with dormant maintainers pushed info-stealers through postinstall scripts. The registry was fine; the accounts were not.

Continue Readingnpm Hijacking Wave: coa, rc, node-ipc and Stolen Maintainers
Read more about the article Nobelium’s Password Spray: The Channel Becomes the Supply Chain

Nobelium’s Password Spray: The Channel Becomes the Supply Chain

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security

The SolarWinds actor returned with no implant at all — sprayed passwords, replayed tokens, and delegated partner admin rights over 609 channel companies.

Continue ReadingNobelium’s Password Spray: The Channel Becomes the Supply Chain
Read more about the article Facebook’s BGP Outage: Six Hours, Self-Inflicted, Total

Facebook’s BGP Outage: Six Hours, Self-Inflicted, Total

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security

One maintenance command withdrew Facebook’s backbone routes, took DNS with it, and locked engineers out of the fix. The outage defended itself.

Continue ReadingFacebook’s BGP Outage: Six Hours, Self-Inflicted, Total
Read more about the article Apache Path Traversal: CVE-2021-41773 Broke in 24 Hours

Apache Path Traversal: CVE-2021-41773 Broke in 24 Hours

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security/Web & API Security

A single encoded GET walked out of Apache’s docroot, and the first patch didn’t hold. Inside the October 2021 traversal zero-day scramble.

Continue ReadingApache Path Traversal: CVE-2021-41773 Broke in 24 Hours
Read more about the article REvil Takedown: How 14 Arrests Killed Ransomware’s Worst Brand

REvil Takedown: How 14 Arrests Killed Ransomware’s Worst Brand

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Emerging Tech & Architecture/Ransomware & Malware/Security

October 2021’s FSB operation ended REvil with arrests, asset seizures, and infrastructure capture. The talent lived on elsewhere.

Continue ReadingREvil Takedown: How 14 Arrests Killed Ransomware’s Worst Brand
Read more about the article FORCEDENTRY: The Zero-Click iMessage Exploit That Beat BlastDoor

FORCEDENTRY: The Zero-Click iMessage Exploit That Beat BlastDoor

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security/Web & API Security

NSO’s FORCEDENTRY turned a PDF font parser into a tiny computer and owned iPhones with no tap. The Citizen Lab anatomy and Apple’s Lockdown Mode response.

Continue ReadingFORCEDENTRY: The Zero-Click iMessage Exploit That Beat BlastDoor
Read more about the article T-Mobile 2021: 76.6 Million Records Through One Unprotected API

T-Mobile 2021: 76.6 Million Records Through One Unprotected API

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Identity & Phishing/Security/Web & API Security

No zero-days, no malware — just weak router credentials, a flat network, and an internal API with no authentication. The Binns breach rewrote telecom disclosure playbooks.

Continue ReadingT-Mobile 2021: 76.6 Million Records Through One Unprotected API
Read more about the article Poly Network: The $611M Bridge Hack That Got Returned

Poly Network: The $611M Bridge Hack That Got Returned

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cryptography & PKI/Security

A forged keeper-list substitution drained $611M across three chains. Then the attacker gave it all back. The bridge bug class that defined Web3’s worst year.

Continue ReadingPoly Network: The $611M Bridge Hack That Got Returned
Read more about the article ProxyShell: The August 2021 Exchange Pillage After Hafnium

ProxyShell: The August 2021 Exchange Pillage After Hafnium

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security/Web & API Security

Three patched-but-unapplied Exchange bugs chained into unauthenticated RCE. Webshells, mailbox theft, and ransomware followed at population scale within two weeks.

Continue ReadingProxyShell: The August 2021 Exchange Pillage After Hafnium
Read more about the article PetitPotam and ESC8: The NTLM Relay Chain That Owned Active Directory

PetitPotam and ESC8: The NTLM Relay Chain That Owned Active Directory

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Identity & Phishing/Security

PetitPotam coerced Windows machines to authenticate, AD CS web enrollment happily minted a DC certificate, and domains fell in an afternoon. The relay class is still with us.

Continue ReadingPetitPotam and ESC8: The NTLM Relay Chain That Owned Active Directory
Read more about the article HiveNightmare: The Two-Line Bug That Leaked Every Local Password Hash

HiveNightmare: The Two-Line Bug That Leaked Every Local Password Hash

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Cloud & Infrastructure/Security

One broken inheritance flag left Windows SAM, SYSTEM, and SECURITY hives readable by any user. With shadow copies in play, that meant every local NTLM hash on the box.

Continue ReadingHiveNightmare: The Two-Line Bug That Leaked Every Local Password Hash
Read more about the article Pegasus Zero-Click: Spyware That Needed No Click at All

Pegasus Zero-Click: Spyware That Needed No Click at All

  • Post author:Prabhu Kalyan Samal
  • Post published:September 3, 2026
  • Post category:Emerging Tech & Architecture/Identity & Phishing/Security

The Pegasus Project exposed 50,000 targeted numbers and a hard truth: modern mercenary spyware infects phones through iMessage and WhatsApp without the victim doing anything.

Continue ReadingPegasus Zero-Click: Spyware That Needed No Click at All
  • Go to the previous page
  • 1
  • …
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • Go to the next page
Press Escape to close the search panel.

Categories

  • AI Security (1)
  • Aviation and Aerospace Security (9)
  • Beyond Security (1)
  • Security (339)
  • Technology (62)

Recent Posts

  • Abusing OIDC in CI/CD: A Step-by-Step Tutorial on GitHub Actions Token Trust Chains
  • How to Hash Passwords in 2026: Argon2id, bcrypt and the NIST Baseline
  • Terraform State: The Most Sensitive File in Your Infrastructure
  • Hands-On Container Escape Lab: Privilege Escalation from Pod to Node with Real Commands
  • JWT Security: alg=none, Key Confusion and Why the Header Lies
  • Weekly Threat Intel: Supply Chain Compromises, Autumn CVE Exploitation and Infostealer Trends
  • UEFI Secure Boot and BlackLotus: The Boot Chain of Trust Under Attack
  • Weekly Threat Intel: Edge CVEs, MCP Agent Abuse, Stealer Cashouts
  • HTTP/3 and QUIC: How the Web Moved to a New Transport
  • Dependency Confusion Lab: Reproduce and Defend Your Pipeline
  • Cosign Signing and Verification Lab: Sign, Verify, Enforce
  • Kerberos Attack Paths: Golden Tickets, Silver Tickets and Kerberoasting
  • DNSSEC Explained: Chain of Trust, NSEC3 and the October 2026 Root Rollover
  • BOLA and Broken Auth API Attacks with Burp Suite: Lab Guide
  • OWASP ZAP DAST Lab: Authenticated API Scanning Explained

Archives

  • September 2026 (260)
  • August 2026 (98)

Newsletter

Get all latest content delivered to your email a few times a month. Updates and news about all categories will send to you.
Email is required Email is not valid
This field is required
Thanks for your subscription.
Failed to subscribe, please contact admin.
Hmmnm

Our Other Sites

  • Hmmnm.in
  • Odia.hmmnm.in

Quick Links

  • Security Services
  • Learning Paths
  • About Us
  • Contact
  • Blog
  • Privacy Policy
  • Disclaimer
  • Security Products
  • Terms of Service

Contact Info

  • 📧 contact@hmmnm.com
  • 🌐 hmmnm.com
in
© 2026 @Hmmnm

We use cookies to understand how the site is used and to improve your experience. You can accept analytics cookies or continue with essential cookies only. Privacy Policy

  • Home
  • Blog
  • Security
  • Experience
  • About Us
  • Services
  • Contact