Internet Explorer CVE-2020-0674: The Zero-Day Advisory That Opened 2020

On 17 January 2020, Microsoft published ADV200001, a rare out-of-band advisory for CVE-2020-0674, a remote code execution flaw in the scripting engine used by Internet Explorer 9 and 11 that the company confirmed was being exploited in limited targeted attacks. There was no patch yet, only mitigations and workarounds, and defenders spent nearly a month exposed until the 11 February 2020 cumulative update shipped the fix. This piece reconstructs the advisory, the memory-corruption mechanics in the script engine, why IE was still a live attack surface in 2020, and what the episode taught about mitigations-first disclosure.

Continue ReadingInternet Explorer CVE-2020-0674: The Zero-Day Advisory That Opened 2020

After Soleimani: The January 2020 US-Iran Cyber Alert Wave

Within hours of the 3 January 2020 strike that killed Iranian general Qasem Soleimani, security agencies on both sides of the Atlantic braced for cyber retaliation. On 6 January 2020 a U.S. federal website, the Federal Depository Library Program, was defaced with pro-Iran messaging and an image of a bloodied President Trump, claimed by a group calling itself Iran Silk Hat, while CISA and the FBI renewed warnings about possible Iranian attacks on critical infrastructure. This retrospective maps the verified incidents of that week, separates hype from evidence, and explains why agencies treated the moment as a genuine escalation trigger despite limited actual damage.

Continue ReadingAfter Soleimani: The January 2020 US-Iran Cyber Alert Wave

BGP Hijacking’s 2023 Resurgence, and What RPKI Fixed

All through 2023, route leaks and suspected BGP hijacks kept redirecting chunks of internet traffic — events touching Rostelecom-linked infrastructure, financial services, and a persistent streak of cryptocurrency-targeting interception paths. None matched the famed mass redirections of prior years, but the pattern of brief, deniable, hard-to-attribute incidents kept routing security in the research headlines. This year-end review explains how BGP trust fails, walks the 2023 incident ledger with appropriately hedged attribution, and covers the defensive state of the art: RPKI signing crossing majority coverage, MANRS norms, and external route monitoring.

Continue ReadingBGP Hijacking’s 2023 Resurgence, and What RPKI Fixed

Magecart’s 2024 Resurgence: Skimming in the Polyfill.io Aftermath

Through 2024, digital skimming returned to threat reports’ front pages: Magecart-style attacks compromised hundreds of storefronts via compromised third-party JavaScript, supply-chain infections like polyfill.io’s June domain takeover injected malicious scripts into vast numbers of pages, and PCI DSS 4.0’s script-integrity requirements (6.4.3 and 11.6.2) approached their March 2025 enforcement deadline. This survey digests the modern skimming kill chain — injection, exfiltration, and evasion — the major 2024 campaigns, and the compliance clock turning client-side risk into boardroom math.

Continue ReadingMagecart’s 2024 Resurgence: Skimming in the Polyfill.io Aftermath

FortiManager Zero-Day (FortiJump): CISA Escalation Explained

On October 23, 2024, Fortinet confirmed CVE-2024-47575 — a CVSS 9.8 missing-authentication flaw in the FortiManager FGFM protocol that China-nexus actor UNC5850 had exploited since summer to jump from exposed managers into fleets of managed FortiGates with a custom DeepMove implant. CISA KEV-listed it within days, forcing two-week patch deadlines across federal and enterprise fleets. This account reconstructs the protocol bug, the DeepMove persistence, the fleet-jump blast radius, and the management-plane hardening it made mandatory.

Continue ReadingFortiManager Zero-Day (FortiJump): CISA Escalation Explained

Ivanti Connect Secure Zero-Days: The Edge-Appliance Crisis

January 2024 opened with the year’s first appliance crisis: two pre-authentication zero-days in Ivanti Connect Secure that nation-state actors had already exploited, followed by integrity-check failures and a reset wave across thousands of enterprise VPNs. This account covers CVE-2023-46805 and CVE-2024-21887, the mass exploitation between disclosure and patch, the customers whose breaches surfaced weeks later, and why edge appliances became the year’s most contested patch surface.

Continue ReadingIvanti Connect Secure Zero-Days: The Edge-Appliance Crisis

Pulse Secure VPN Zero-Days: When Remote Access Became the Front Door

Pre-auth Pulse Secure exploits handed APT crews and ransomware affiliates appliance-level control of the VPNs that carried pandemic remote work. How credential capture and patch-surviving persistence rewrote edge-appliance incident response.

Continue ReadingPulse Secure VPN Zero-Days: When Remote Access Became the Front Door

Chrome V8 Zero-Day CVE-2021-21148: Anatomy of a Drive-By

Google’s February 2021 emergency Chrome patch opened a record zero-day year. This incident file breaks down how the V8 heap overflow worked, how it chained with a sandbox escape, why watering-hole delivery leaves no trace, and what fleet-level browser defenses it forced.

Continue ReadingChrome V8 Zero-Day CVE-2021-21148: Anatomy of a Drive-By