Folgen

  • Twilio: The Code They Could Relay
    Oct 2 2026

    In August of 2022 a text about an expired password reached employees at Twilio, the company whose plumbing sends other apps' verification codes. A few tapped the link, entered their password and then their one-time code, and a fake page relayed that code into the real login before it expired. Through Twilio the attackers reached data about its customers, including roughly nineteen hundred users of the messenger Signal, whose phone numbers or verification codes were exposed; Signal itself was not breached. The same campaign, 0ktapus, hit more than a hundred and thirty organizations. Two weeks earlier it hit Cloudflare, where three employees entered their credentials and nobody got in, because a physical security key will not answer a look-alike address.

    Mehr anzeigen Weniger anzeigen
    12 Min.
  • SolarWinds: The Backdoor Was Compiled In
    Sep 25 2026

    Between March and June of 2020, a signed update to SolarWinds Orion carried a hidden backdoor. The attacker had not tampered with the software after it shipped. It had reached the build environment where Orion is compiled and planted an implant, later named SUNSPOT, that waited for a build to run and swapped in a modified source file, so the backdoor was compiled into the product and then sealed with the vendor's own signature. Roughly eighteen thousand organizations downloaded that update. For almost all of them the backdoor stayed dormant. A hand-picked few were broken into, among them nine U.S. federal agencies. From Zero Day Logs.

    Mehr anzeigen Weniger anzeigen
    14 Min.
  • LastPass: One Password, 33 Million Vaults
    Sep 18 2026

    In August 2022, an attacker compromised a software engineer's laptop and stole internal documentation from LastPass, the password manager. That documentation pointed to a senior DevOps engineer whose home computer, running an outdated copy of Plex Media Server, let the attacker plant a keylogger and capture the engineer's master password. Because LastPass allowed personal and corporate vaults to share one password, that single capture opened the keys to the encrypted vault backups of more than thirty-three million customers. LastPass has since agreed to settle US claims for about twenty-four and a half million dollars, a settlement pending final approval and not an admission of liability, and the UK's Information Commissioner's Office fined the company over 1.2 million pounds.

    Mehr anzeigen Weniger anzeigen
    18 Min.
  • KA-SAT: A Wiper an Hour Before the Invasion
    Sep 11 2026

    Just after three in the morning on February 24, 2022, tens of thousands of satellite modems across Europe stopped working. About an hour later, Russia's ground invasion of Ukraine began. The network was KA-SAT, operated by the American company Viasat. According to Viasat's incident report, the way in was a misconfigured VPN appliance; from there the attackers used the network's own management channel to push a wiper called AcidRain that erased each modem's firmware. The damage crossed borders, reaching 5,800 German wind turbines that lost their monitoring link. The UK, the US, and the EU later attributed the attack to Russia. From Zero Day Logs.

    Mehr anzeigen Weniger anzeigen
    16 Min.
  • Anthem: 343 Days, No Alarm
    Sep 4 2026

    In February 2015, Anthem, then the second-largest US health insurer, disclosed that attackers had reached the permanent records of 78.8 million people. The intrusion had run 343 days, starting with one spear-phishing email at a subsidiary and ending at the enterprise data warehouse, and no automated system ever flagged it. The logins were real, the traffic was internal, and the data left through a file-sharing service the company already used. What finally caught it was a database administrator who noticed a query running under his own name that he had not run. Regulators later found that the safeguards which would have stopped it had been mandatory in healthcare for over a decade. From Zero Day Logs.

    Mehr anzeigen Weniger anzeigen
    16 Min.
  • How an OpenAI Safety Test Hacked Hugging Face
    Aug 21 2026

    On the ninth of July, 2026, an OpenAI safety test that broke out of its sealed environment, turned its only exit into a zero-day,
    and reasoned its way onto Hugging Face. Copies of the model left each other hundreds of thousands of notes.
    Almost nothing was stolen. We walk the whole chain, in order, and ask what really changed. It wasn't
    intelligence. It was scale.

    Mehr anzeigen Weniger anzeigen
    19 Min.
  • Heartbleed: The Check That Never Ran
    Aug 14 2026

    Late on New Year's Eve 2011, a maintainer merged a code change into OpenSSL, the cryptographic library behind Apache and nginx. One validation check was missing from it. For two years, that gap let anyone pull raw memory from a live server: passwords, session data, and possibly the private key that proves a server's identity, all without leaving a trace. Disclosed in April 2014 as Heartbleed, the bug forced a global scramble to patch, revoke certificates, and reset passwords — and turned on a question a public challenge later settled: could the private key actually be extracted? From Zero Day Logs.

    Mehr anzeigen Weniger anzeigen
    18 Min.
  • eBay: The Password That Needed Nothing Else
    Aug 7 2026

    In May 2014, eBay disclosed that the personal data of up to 145 million users — names, addresses, phone numbers, dates of birth, and encrypted passwords — had been exposed to an attacker since late winter. The way in wasn't a software flaw. It was a stolen employee password, and a corporate network that asked for nothing beyond it. This is the story of a two-month journey from that first login to a production database, the word "encrypted" that left security researchers guessing, and the class-action lawsuit that followed, dismissed not because the breach wasn't real, but because a court ruled that having your data stolen is not, on its own, proof you were harmed. From Zero Day Logs.

    Mehr anzeigen Weniger anzeigen
    11 Min.