UEFI Secure Boot and BlackLotus: The Boot Chain of Trust Under Attack
How UEFI Secure Boot anchors trust in firmware, how BlackLotus bypassed it via CVE-2022-21894, and why revocation took years to roll out.
How UEFI Secure Boot anchors trust in firmware, how BlackLotus bypassed it via CVE-2022-21894, and why revocation took years to roll out.
SPDX vs CycloneDX compared honestly, how to generate SBOMs that match production, and the failure modes that sink real adoption — plus the EU CRA deadlines now in force.
On April 24, 2024, CISA and the FBI advised every Sisense customer to rotate credentials after attackers compromised the BI vendor’s development environment — and by week’s end, Sisense-issued AWS keys were circulating publicly. This piece reconstructs the five-day arc from detection to contained, explains why business-intelligence platforms are credential funnels that turn vendor CI/CD breaches into customer incidents, and extracts the third-party-risk doctrine the episode left behind for every embedded-analytics supply chain.
Cl0p’s June 2023 listing waves turned the MOVEit breach into a running census — 2,700+ organizations and ~93M individuals per Emsisoft tallies. The economics of encryption-free extortion.
MSI’s ransomware extorted Intel BootGuard OEM signing keys onto underground markets — keys that certify firmware as bootable. Key ceremony lessons.
GoDaddy’s 2023 filing admitted intermittent intruder access since 2020, malware in cPanel servers, and email interception affecting ~6.95M customers.
Through 2024, digital skimming returned to threat reports’ front pages: Magecart-style attacks compromised hundreds of storefronts via compromised third-party JavaScript, supply-chain infections like polyfill.io’s June domain takeover injected malicious scripts into vast numbers of pages, and PCI DSS 4.0’s script-integrity requirements (6.4.3 and 11.6.2) approached their March 2025 enforcement deadline. This survey digests the modern skimming kill chain — injection, exfiltration, and evasion — the major 2024 campaigns, and the compliance clock turning client-side risk into boardroom math.
When Sansec disclosed in late June 2024 that the polyfill.io domain had been sold and its hosted script rewritten to inject mobile-only scam redirects, hundreds of thousands of embedded sites — WordPress themes among them — discovered they had inherited an implant, invisible to desktop QA by design. This account traces the Funnull acquisition chain, the conditional payload mechanics, Cloudflare’s mirror intervention, the DNS-harassment retaliation, the 2025 arrests, and the inventory lesson every site owner still owes themselves.
The most patient supply-chain attack ever caught — a two-year maintainer infiltration that planted an SSH backdoor into xz-utils release tarballs, discovered in March 2024 only because one engineer noticed 500 milliseconds of latency. This account traces the Jia Tan persona from helpful contributor to release engineer, the test-file obfuscation and build-stage injection, the systemd/sshd target chain, the near-miss that kept stable distros clean, and the trust-model reforms that rippled through open source.
March 2024’s CVE-2024-27198 let unauthenticated attackers mint admin accounts on self-hosted TeamCity CI servers, converting every connected build agent into attacker-controlled execution holding source, secrets and signing keys. This piece covers the alternate-path authentication bypass, the companion path traversal, the ransomware crews that queued within days, and the year’s hard-learned rule that build infrastructure deserves domain-controller-grade security.
Remote-access maker AnyDesk confirmed in February 2024 that attackers had compromised production systems using valid credentials traced to infostealer logs — forcing a certificate rotation, password resets, and a rushed 8.1.1 release whose code-signing was intact but whose credibility needed rebuilding. This piece covers the infostealer-to-supply-chain escalation path that rewired vendor-risk thinking, and why remote-admin tooling became a tier-one identity perimeter.
On 13 November 2023, DP World Australia disconnected its port systems from the internet to contain an intrusion — and container operations at Sydney, Melbourne, Brisbane and Fremantle stopped cold, stranding roughly 30,000 containers for three days. Operations resumed by 16 November, personnel data exposure was later confirmed, and no ransom payment was disclosed. The episode became Australia’s reference case for cyber-driven supply-chain disruption and a model of disciplined containment, rapid restoration and honest capacity communication under SOI-Act scrutiny.