23andMe Credential Stuffing: When Relatives Are the Payload

Reused passwords took over 14,000 23andMe accounts, then the DNA Relatives feature amplified the access into profile data for 6.9 million genetically-linked users. The October 2023 breach rewrote breach math: your exposure now includes every relative’s password hygiene.

Continue Reading23andMe Credential Stuffing: When Relatives Are the Payload

Mr. Cooper Mortgage Breach: The Week Payments Stopped

When one of America’s largest mortgage servicers went dark for a week, the harm went far beyond stolen data. The Mr. Cooper incident — detected October 24, disclosed October 31, 2023 — halted payments, escrow, and payoffs for millions of borrowers, and later filings put the notification count near 14.7 million people with Social Security numbers and bank account details in the mix. This account covers the stolen-credential entry, the outage that regulators treated as the real injury, the mortgage-sector dependencies that amplified it, and the durable lessons for any payment-critical firm.

Continue ReadingMr. Cooper Mortgage Breach: The Week Payments Stopped

CDK Global Ransomware: US Car Dealerships Run on Pen and Paper

On June 19, 2024, ransomware hit CDK Global’s dealer management platform — the operational nervous system of ~15,000 North American dealerships — and a second strike during recovery extended the outage for weeks while finance desks, service bays and OEM ordering reverted to paper and fax. This account covers the June 19/22 double-hit timeline, the billion-dollar industry loss estimates, why DMS lock-in made fallback manual rather than competitive, and the concentration-risk docket the incident left for every regulator to cite.

Continue ReadingCDK Global Ransomware: US Car Dealerships Run on Pen and Paper

Squarespace Domain Hijackings: The 2024 GoDaddy Migration Aftermath

After Squarespace absorbed roughly 10 million domains from Google Domains in mid-2024, attackers discovered a seam: legacy Google-account login flows stopped being enforced, and formerly eNom-transferred .dev/.us domains could be taken over by re-registering then-unlinked accounts. From late June through July, crypto-draining hijacks of high-value domains — including Matomo founder trust abusing Squarespace lock states — left registry operators and site owners scrambling. This account traces the migration mechanics, the attack window, and the DNS tenure lessons.

Continue ReadingSquarespace Domain Hijackings: The 2024 GoDaddy Migration Aftermath

TfL 2024: A 17-Year-Old, a Social Engineer’s Approach and Oyster Chaos

On September 5, 2024, Transport for London detected an intrusion begun days earlier through social engineering of staff — and within a week a 17-year-old was arrested, then charged under the Computer Misuse Act, for a breach that exposed contact details and the bank details of roughly 3,000 Oyster refund customers. This account reconstructs the phishing entry, the lateral movement, the containment that took status boards and the refund portal offline, the NCSC-NCA response, and the municipal-security lessons that outlasted the headlines.

Continue ReadingTfL 2024: A 17-Year-Old, a Social Engineer’s Approach and Oyster Chaos

Windows Downdate: Downgrade Attacks Against the OS Itself

At DEF CON 32 in August 2024, SafeBreach’s Alon Leviev unveiled Downdate — a technique that abuses the Windows Modules Installer, TrustedInstaller privileges,and deliberately-eased vbsm manifest permission to silently roll back fully-patched Windows binaries to vulnerable prior versions, re-opening fixed BitLocker bypasses and Hyper-V escapes on current builds. This account explains the downgrade mechanics, the CVE-2024-21430 fix timeline, and why the research redefined patch currency as a security property worth defending.

Continue ReadingWindows Downdate: Downgrade Attacks Against the OS Itself