Colonial Pipeline Ransomware: One Password, 17 Emergency States

DarkSide entered through a no-MFA legacy VPN password, exfiltrated 100 GB, and encrypted Colonial’s IT — prompting a precautionary shutdown of 45% of East Coast fuel supply. Anatomy of the most policy-consequential ransomware ever.

Continue ReadingColonial Pipeline Ransomware: One Password, 17 Emergency States

Codecov Breach: The CI Script That Leaked Build Secrets for Months

A tampered Codecov Bash Uploader quietly shipped CI environment variables — cloud keys, tokens, signing material — to attackers for two months. The curl-pipe-bash trust model dissected, and how build supply-chain security was rewritten after.

Continue ReadingCodecov Breach: The CI Script That Leaked Build Secrets for Months

HAFNIUM and Exchange Zero-Days: The 30,000-Server Compromise

Four zero-days in on-premises Microsoft Exchange let HAFNIUM and ten follow-on crews own mail servers at tens of thousands of organisations. The anatomy of the SSRF-to-web-shell chain, the PATCH NOW scramble, and why patching was not remediation.

Continue ReadingHAFNIUM and Exchange Zero-Days: The 30,000-Server Compromise

CD Projekt Red Ransomware: The Source-Code Auction That Failed

HelloKitty ransomware encrypted CDPR’s network and stole Cyberpunk 2077 and Witcher 3 source code — then auctioned it on a crime forum after the studio refused to pay. The incident file on IP extortion, auction economics, and the no-ransom playbook.

Continue ReadingCD Projekt Red Ransomware: The Source-Code Auction That Failed

Dependency Confusion: How a Researcher Hacked Apple and Microsoft

No exploits, no stolen credentials — Alex Birsan’s February 2021 research got code executed inside 35+ major companies by registering their internal package names on public registries and letting version arithmetic do the rest. The incident file on the cheapest supply-chain attack ever demonstrated.

Continue ReadingDependency Confusion: How a Researcher Hacked Apple and Microsoft

Oldsmar Water Plant Hack: The Five-Minute SCADA Wakeup Call

A remote intruder raised a Florida treatment plant’s lye setpoint from 100 to 11,100 ppm and an operator watching the screen reverted it in minutes. The incident file on shared passwords, exposed TeamViewer, and why OT security failed at a municipal water utility.

Continue ReadingOldsmar Water Plant Hack: The Five-Minute SCADA Wakeup Call