CitrixBleed CVE-2023-4966: Session Tokens Straight From Memory

CVE-2023-4966 let attackers read valid session tokens out of NetScaler memory and inherit authenticated sessions wholesale — MFA already passed. CISA’s Emergency Directive 23-08 forced hunts and rebuilds as LockBit monetized the access.

Continue ReadingCitrixBleed CVE-2023-4966: Session Tokens Straight From Memory
Read more about the article The First 24 Hours of a Ransomware Attack: Survival Playbook
Ransomware countdown first 24 hours timeline

The First 24 Hours of a Ransomware Attack: Survival Playbook

Change Healthcare lost the claims pipeline of a nation in hours. This minute-by-minute playbook covers hour zero containment, the command structure by hour four, backup verification, pay/no-pay, regulatory clocks — and the non-technical decisions that decide survival.

Continue ReadingThe First 24 Hours of a Ransomware Attack: Survival Playbook

Midnight Blizzard vs Microsoft: Legacy Tenant to Executive Email

A defunct test tenant, a legacy password without MFA, and a residential-proxy password spray gave Russia’s Midnight Blizzard a foothold inside Microsoft’s own corporate estate in January 2024 — culminating in stolen executive email and a downstream supplier breach wave. This account explains the password-spray tradecraft, how the actors abused OAuth apps to mine mailboxes, why the failure drew a czar-memo mea culpa, and the SEC disclosure mechanics that made the saga public.

Continue ReadingMidnight Blizzard vs Microsoft: Legacy Tenant to Executive Email