online│syscfg.research
utc
syscfg://research
syscfg@research:~$ ls -lt ./archive/

Archive

162 articles across 3 years

2026

81 articles
2026-09-11Original31 Days Inside a Public SSH Honeypot: 1.25 Million Events, Multi-Architecture Malware, and What Automated Attackers Actually DoPublished
2026-09-12OriginalTesting a Four-Year-Old Botnet Fingerprint: The mdrfckr Campaign's Published HASSH Is Dead and Its Payload Never ChangedPublished
2026-09-14OriginalOne Key, 511 Hosts: How a Shared SSH Public Key Fingerprints a Botnet That IP Blocklists Cannot SeePublished
2026-09-15OriginalSomebody Read the Site, Then Came Back Every Week: A Month of Targeted Credential Attacks Against This Server's Own UsernamesPublished
2026-09-05Vuln ResearchEchoLeak: Four Defences, Four Bypasses, and What Zero-Click Prompt Injection Says About Filtering an Unconstrained CapabilityPublished
2026-09-19BreachFrom a Bing Search to Domain-Wide Akira in 44 Hours: SEO Poisoning, wbadmin and the Software Already on the NetworkPublished
2026-09-13MalwareTwo Ways Into the Build: ChainDrop's npm Worm, XCSSET v40, and Why Valid Provenance Is Not a DefencePublished
2026-09-16BreachThere Is No C2 Server To Block: EtherRAT, TukTuk, and Command and Control Built Entirely on SaaSPublished
2026-09-17Vuln ResearchOne Bug, Two Official CVSS Scores: CVE-2025-25249, PivotC2, and the 1.7 Points That Decide Whether Anyone Gets PagedPublished
2026-09-18Hardware$159 of Hardware Breaks Confidential Computing: DDRop, Dropped DDR5 Writes, and Why Encryption Is Not FreshnessPublished
2026-09-22Threat IntelNobody Logged In: How ShinyHunters Emptied Hundreds of Salesforce Tenants Through OAuth Grants Nobody OwnedPublished
2026-09-24BreachAn Extortion Group With a Reputation to Protect: CVE-2026-35273, ShinyHunters, and the FBI Advisory They Want DeletedPublished
2026-09-27HistoryWhen Encryption Was a Weapon: The Cypherpunks, the Crypto Wars, and the Book That Beat the Munitions ListPublished
2026-09-28HardwareSecure Against Whom? The Hardware of Resisting Surveillance, With the Marketing RemovedPublished
2026-10-01MalwareThe Persistence Layer IR Tools Cannot See: LoJax, CosmicStrand, BlackLotus and What It Takes to Find Firmware-Level ImplantsPublished
2026-08-08MalwareWannaCry and EternalBlue: How the NSA's Hoarded Exploit Infected 200,000 Machines in 72 HoursPublished
2026-08-04HistoryThe Fall of Dread Pirate Roberts: How One Stack Overflow Post Ended Silk RoadPublished
2026-08-03Social EngFrom Instagram OGs to $100M Heists: The Rise of the SIM Swapping ScenePublished
2026-07-31HistoryOperation Bayonet: The Dark Web's Most Sophisticated TakedownPublished
2026-07-29HistoryOPSEC Hall of Shame: The Mistakes That Ended CareersPublished
2026-07-25History50 Days of Lulz: The LulzSec Rampage, the Informant, and the FallPublished
2026-07-21HistoryThe COM: How Teenagers Became the Most Disruptive Hackers in AmericaPublished
2026-07-15Social EngThe Fappening: Anatomy of a Two-Year Celebrity Phishing CampaignPublished
2026-07-11HistoryShadowCrew: The Forum That Invented Modern CybercrimePublished
2026-07-10HistoryStuxnet: The First Cyberweapon That Broke Real MachinesPublished
2026-07-09MalwareMirai: How Three College Students Broke the Internet With Default PasswordsPublished
2026-07-07HistoryNotPetya: The $10 Billion Cyberweapon Disguised as RansomwarePublished
2026-07-03MalwareLog4Shell: The CVSS 10.0 Vulnerability Hidden Inside Every Java AppPublished
2026-06-29HistoryColonial Pipeline: The Single Password That Shut Down East Coast Fuel SupplyPublished
2026-06-25ResearchDNS Security: Cache Poisoning, Nation-State Hijacking, and the Protocol That Never Got Security RightPublished
2026-06-21Researchnpm, PyPI, and the Package Manager Attack Surface: How Malicious Code Reaches Millions of DevelopersPublished
2026-06-18HistoryPhineas Fisher and the Hacking Team Breach: Hacktivism as Political Direct ActionPublished
2026-06-15HistoryMt. Gox to Bybit: A History of Cryptocurrency Exchange Hacks and the $10 Billion StolenPublished
2026-06-12HistoryThe Cuckoo's Egg: How a 75-Cent Accounting Error Led to a KGB Spy Hunt in 1986Published
2026-06-07ResearchThe Juniper Backdoor: How the NSA's Cryptographic Weakness Was Repurposed by a Foreign AdversaryPublished
2026-06-02Threat IntelFinFisher, Hacking Team, Pegasus: Inside the Commercial Spyware Industry That Sells Surveillance to GovernmentsPublished
2026-05-31MalwareGameOver Zeus: The $100M Banking Trojan, CryptoLocker, and the Cybercriminal Russia Won't ExtraditePublished
2026-05-28HistoryYahoo's 3 Billion Compromised Accounts: The Breach That Changed Corporate Disclosure LawPublished
2026-05-25HistoryTor and the Dark Web: How a Navy Research Project Became the Infrastructure of the UndergroundPublished
2026-05-23MalwareKaseya and REvil: The Supply Chain Ransomware Attack That Hit 1,500 Businesses on July 4th WeekendPublished
2026-05-18Social EngMGM vs Caesars: The $100M Casino Hack That Defined the Ransomware DebatePublished
2026-05-16Social EngThe Twitter Hack: How a 17-Year-Old Took Over Obama, Biden, and Musk With One Phone CallPublished
2026-05-13HistoryThe RSA SecurID Breach: When Hackers Stole the Keys to 40 Million Two-Factor TokensPublished
2026-05-10HistoryThe Bangladesh Bank Heist: How Lazarus Group Stole $81 Million Through the SWIFT NetworkPublished
2026-05-07HistoryAshley Madison: The Breach That Weaponized Personal Data Against 37 Million PeoplePublished
2026-05-04MalwareConficker: The 15-Million-Machine Botnet That Did Almost NothingPublished
2026-05-03HistoryThe Morris Worm: How a Graduate Student's Experiment Took Down 10% of the Internet in 1988Published
2026-04-30MalwareSpectre and Meltdown: The CPU Vulnerabilities That Affected Every Computer Since 1995Published
2026-04-28Social EngLAPSUS$: The Teenage Hackers Who Breached Microsoft, Nvidia, and Okta with a Phone and a Telegram AccountPublished
2026-04-22HistoryThe Equifax Breach: How an Unpatched Server and an Expired Certificate Exposed 147 Million AmericansPublished
2026-04-18MalwareHeartbleed: The Vulnerability That Proved Critical Open Source Was Running on DonationsPublished
2026-04-13HistoryThe OPM Breach: How China Stole the Personnel Files of Every US Intelligence OfficerPublished
2026-04-09HistoryThe Target Breach: How an HVAC Contractor's Credentials Led to 40 Million Stolen CardsPublished
2026-04-04HistoryThe Sony Pictures Hack: When North Korea Went to War Over a Comedy FilmPublished
2026-03-31MalwareCarbanak: The $1 Billion Bank Heist That Used APT Techniques for ProfitPublished
2026-03-27ResearchBGP Hijacking: The Protocol Flaw That Lets Anyone Reroute the InternetPublished
2026-03-26HistoryXZ Utils Backdoor: How a Two-Year Social Engineering Campaign Nearly Compromised the Linux EcosystemPublished
2026-03-24HistoryAnonymous: From 4chan Raids to Operation Payback and the WikiLeaks WarPublished
2026-03-21HistoryOperation Aurora: How China's Hack of Google Created the APT EraPublished
2026-03-20HistoryThe Shadow Brokers: How the NSA's Most Dangerous Arsenal Was Stolen and LeakedPublished
2026-03-18HistorySolarWinds SUNBURST: How Russia Hid a Backdoor in 18,000 Software Updates and Read US Government Email for Nine MonthsPublished
2026-03-16HardwareWiFi Pineapple: Evil Twin Attacks, Captive Portals, and Public WiFi's Unsolved ProblemPublished
2026-03-13HardwareFlipper Zero Field Guide: Sub-GHz, BadUSB, NFC and the Multi-Tool That Broke Airport Security TheaterPublished
2026-03-09HardwareHackRF One and Software-Defined Radio: How to Listen to Everything the Wireless World Forgot to EncryptPublished
2026-03-06HardwareThe USB Rubber Ducky: HID Injection, Keystroke Attacks and the Reason You Should Never Plug In a Found USB DrivePublished
2026-03-03HardwarePwnagotchi: The AI-Powered Pet That Eats WiFi Handshakes for BreakfastPublished
2026-03-01HardwareO.MG Cable: The Charging Cable That Owns Your MachinePublished
2026-02-26HardwareProxmark3: Cloning Hotel Keys, Office Badges, and Transit Cards in Under 30 SecondsPublished
2026-02-18HistoryBreachForums and the Dark Web Data Economy: How Stolen Records Become FraudPublished
2026-02-17HistoryChange Healthcare: How One Ransomware Attack Broke the US Healthcare Payment SystemPublished
2026-02-13HistoryThe CrowdStrike Outage: How a Content File Took Down 8.5 Million Windows Systems in 79 MinutesPublished
2026-02-10HistoryThe Hacking Team Breach: When the Surveillance Vendor Got HackedPublished
2026-02-08Threat IntelNSO Group and Pegasus: The Mercenary Spyware Industry and the Journalists Who Were Killed Because of ItPublished
2026-02-05HistoryThe Conti Leaks: Inside the Corporate Structure of the World's Most Prolific Ransomware GangPublished
2026-02-02HistoryLazarus Group: How North Korea Funds Its Weapons Program with Stolen CryptocurrencyPublished
2026-01-25Threat IntelVolt Typhoon: China's Pre-Positioned Access to US Critical InfrastructurePublished
2026-01-21Threat IntelSalt Typhoon: How China Breached US Telecom Carriers and Accessed the Wiretap InfrastructurePublished
2026-01-17HistoryLockBit and Operation Cronos: How Law Enforcement Seized the World's Largest Ransomware OperationPublished
2026-01-12HistoryCl0p and MOVEit: The Mass Exploitation Campaign That Hit 2,700 Organizations Without Deploying RansomwarePublished
2026-01-07HistorySandworm and the Ukraine Power Grid: The First Cyberattack to Cut the LightsPublished
2026-01-05Social EngUber and Rockstar: An 18-Year-Old on Bail Breached Both Companies with a Fire TV StickPublished

2025

41 articles
2025-12-29ResearchThe Zero-Day Market: Zerodium, Government Buyers, and the Economics of Undisclosed VulnerabilitiesPublished
2025-12-13Threat IntelThe Snowden Disclosures: How One NSA Contractor Revealed the Architecture of Global SurveillancePublished
2025-12-10HistoryKevin Mitnick: The Phone Phreak Who Became the World's Most Famous HackerPublished
2025-12-06HistoryANOM: How the FBI Secretly Built and Operated the Encrypted Phone Network Used by 300 Criminal SyndicatesPublished
2025-12-03MalwareLumma Stealer v5: RSA-4096 C2 Key Exchange and Hardware-Bound Session ProtocolPublished
2025-11-26MalwareStealC v2: HTTP/2 C2 Transport and Builder Leak AnalysisPublished
2025-11-24Threat Intelnpm Supply Chain Attack: react-utils-core Delivers XWorm RAT to 14,000 ProjectsPublished
2025-11-22MalwareEDR Evasion in 2026: LOLBin Chains, Sleep Masking, and the Decline of BYOVDPublished
2025-11-18Threat IntelMeduza Stealer: Mapping 140+ Active C2 Panels via Certificate TransparencyPublished
2025-11-15Threat IntelRansomware Infrastructure OSINT: Mapping Negotiation Portals and Affiliate C2 ClustersPublished
2025-11-11MalwareAtomic macOS Stealer: Notarization Abuse, Gatekeeper Bypass, and Keychain ExtractionPublished
2025-11-08MalwareXWorm RAT: Configuration Extraction, C2 Protocol Analysis, and Campaign AttributionPublished
2025-11-04MalwareRisePro vs Vidar: Tracking Stealer Fork Divergence Across 18 Months of CampaignsPublished
2025-11-01Threat IntelJARM Fingerprinting Cobalt Strike: Active Detection of Malleable C2 Profiles at ScalePublished
2025-10-22ResearchDetecting AI-Generated Phishing at Scale: ML Approaches and the Accuracy GapPublished
2025-10-19ResearchWriting Effective Sigma Rules for LOLBin Detection in Production SIEMsPublished
2025-10-18MalwareQakBot and Operation Duck Hunt: 15 Years of Malware, One FBI Uninstaller, and Another ResurrectionPublished
2025-10-17MalwareMaze Ransomware and the Invention of Double ExtortionPublished
2025-10-15BreachProxyLogon: How Four Exchange Zero-Days Compromised 250,000 Servers in 72 HoursPublished
2025-10-11MalwareEmotet: The Malware That Sold Beachheads, the Takedown That Used Its Own Update Channel, and the ResurrectionPublished
2025-10-06HistoryOperation Chanology: How a Leaked Tom Cruise Video Turned a Trolling Collective Into a Global MovementPublished
2025-10-03BreachThe Snowflake Campaign: How 165 Companies Lost Their Data to Stealer Logs and No MFAPublished
2025-10-02ResearchBEAST, POODLE, FREAK, DROWN, ROBOT: How a Decade of Attacks Built TLS 1.3Published
2025-09-29HistoryThe Stratfor Hack: Jeremy Hammond, FBI Informant Sabu, and the Entrapment ControversyPublished
2025-09-16MalwareCryptoLocker: The Ransomware That Invented the Modern Extortion ModelPublished
2025-09-13ResearchWEP, WPA, KRACK, and Dragonblood: How Wi-Fi Security Broke and Rebuilt ItselfPublished
2025-09-09ResearchSocial Engineering and Pretexting: The Attack Surface Security Training Can't FixPublished
2025-08-26BreachThe Internet Archive Hack: 31 Million Users, an Exposed Zendesk Token, and a DDoS from a Completely Different AttackerPublished
2025-08-22HistoryThe Cap'n Crunch Whistle and the Birth of Hacking Culture: A History of Phone PhreakingPublished
2025-08-18HistoryThe $1.5 Billion Bybit Hack: How Lazarus Group Compromised a Hardware Wallet Signing FlowPublished
2025-08-15HistoryThe HBGary Federal Hack: SQL Injection, Password Reuse, and 68,000 EmailsPublished
2025-08-12Threat IntelThe NSA's ANT Catalog: A Product Brochure for Backdoors in EverythingPublished
2025-08-08HistoryAaron Swartz, JSTOR, and the CFAA: When Computer Crime Law Ate ItselfPublished
2025-08-06HistoryFancy Bear, Guccifer 2.0, and the 2016 DNC Hack: Inside Russia's Election Interference OperationPublished
2025-08-03Threat IntelThe Credential Stuffing Economy: Combolists, Stealer Logs, and the Infrastructure of Account TakeoverPublished
2025-07-31HistoryREvil: Kaseya, the FBI's Withheld Decryptor, the Russia Arrests, and the Geopolitics of Ransomware TolerancePublished
2025-07-14Threat IntelThe Internet Research Agency: How Russia's St. Petersburg Troll Farm Actually WorkedPublished
2025-07-11ResearchSQL Injection: 25 Years on OWASP's Top 10, From CardSystems to MOVEitPublished
2025-07-09ResearchCellebrite UFED: The Mobile Extraction Tool Used by 100+ Countries and Its Security ImplicationsPublished
2025-07-01HistoryOperation Onymous: 400 Tor Sites Taken Down, One Unanswered Question About HowPublished
2025-02-13Nation-StateMoonlight Maze: The 1996 Russian Pentagon Hack That Started It All - and Its DNA in Modern Turla MalwarePublished

2024

40 articles
2024-12-25Nation-StateMarriott/Starwood: The Chinese Intelligence Operation Hidden in a Hotel Loyalty DatabasePublished
2024-12-22BreachThe LastPass Breach: When the Password Manager Gets BreachedPublished
2024-12-19Breach23andMe: How a Credential Stuffing Attack Became a Genetic Data DisasterPublished
2024-12-18BreachLinkedIn 2012: 117 Million Unsalted SHA-1 Password Hashes and the Four-Year Hidden BreachPublished
2024-12-14Vuln ResearchBlueKeep: The Wormable RDP Vulnerability That Kept the Security World Up at NightPublished
2024-12-11BreachAdobe 2013: 153 Million Records, 3DES-ECB Passwords, and the Crossword-Puzzle CrackPublished
2024-12-03Nation-StateDigiNotar: How Iran Compromised a Certificate Authority to Spy on 300,000 UsersPublished
2024-12-02Vuln ResearchPrintNightmare: How an Accidental GitHub Post Handed Ransomware Gangs a Domain Takeover 0-DayPublished
2024-11-28Nation-StateTurla/Snake: Russia's FSB Malware That Has Run Undetected for 20 YearsPublished
2024-11-24Threat IntelEmotet, TrickBot, Ryuk: The Three-Stage Ransomware Chain That Devastated HealthcarePublished
2024-11-23Nation-StateAPT41 / Double Dragon: China's Threat Actor That Does Both Espionage and CybercrimePublished
2024-11-19BreachOkta's Serial Breaches: How the World's Top Identity Provider Got Hacked TwicePublished
2024-11-14BreachT-Mobile's Seven Breaches: How America's Carrier Got Hacked Again and AgainPublished
2024-11-12BreachGoDaddy's Multi-Year Compromise: Malware in the Hosting InfrastructurePublished
2024-11-10BreachUber 2016: The $100K Cover-Up That Sent a CSO to TrialPublished
2024-11-07Nation-StateLazarus Group's Crypto Heists: $625M Ronin Hack and North Korea's Blockchain Revenue StreamPublished
2024-11-05Vuln ResearchFollina: The Zero-Day That Let Word Documents Execute Code Without MacrosPublished
2024-11-03Nation-StateOperation Dark Seoul: North Korea's Simultaneous Wiper Attack on Three Banks and Three TV StationsPublished
2024-10-31MalwareThe Melissa Worm: How a Word Macro Shut Down Microsoft, Intel, and the US Government's Email in 72 HoursPublished
2024-10-26MalwareILOVEYOU: The Worm That Infected 45 Million Computers in 10 Hours and Created No CriminalsPublished
2024-10-25BreachHome Depot 2014: 56 Million Cards, End-of-Life Windows XP on POS Terminals, and the Post-Target Retail Breach EraPublished
2024-10-15MalwareShamoon: The Iranian Wiper That Destroyed 30,000 Saudi Aramco Workstations and Invented State-Sponsored Corporate DestructionPublished
2024-10-14HistoryDNSChanger and Operation Ghost Click: The FBI Malware Takedown That Required Running Criminal Infrastructure as a Public ServicePublished
2024-10-10BreachThe TJX Breach: Wardriving a Parking Lot, WEP Encryption, and 94 Million Stolen CardsPublished
2024-10-07HistoryMafiaboy: The 15-Year-Old Who DDoSed Amazon, eBay, and CNN and Invented the Commercial DDoS IndustryPublished
2024-10-06HistoryOperation Tovar: How the FBI Killed CryptoLocker, Freed 500,000 Victims, and Still Couldn't Catch the GuyPublished
2024-10-05BreachHeartland Payment Systems: 130 Million Cards, a Government Informant Running the Attack, and PCI's Greatest FailurePublished
2024-09-30BreacheBay 2014: 145 Million Accounts, 229 Days of Undetected Access, and the Breach Nobody Got Fined ForPublished
2024-09-28BreachThe Medibank Breach: 9.7 Million Australians' Medical Records, a Refused Ransom, and Published HIV DiagnosesPublished
2024-09-25MalwareCode Red: The IIS Worm That Infected 359,000 Servers in 19 Hours and Attacked the White HousePublished
2024-09-22HistoryKevin Poulsen: The Hacker Who Rigged a Radio Contest by Taking Over the Phone Company to Win a PorschePublished
2024-09-17Nation-StateVault 7: When WikiLeaks Published the CIA's Entire Hacking Toolkit and a Spy Went to Prison for 40 YearsPublished
2024-09-11Nation-StateTriton: The Russian Malware Designed to Disable Safety Systems and Allow Industrial ExplosionsPublished
2024-09-08MalwareBlaster: The Worm That Attacked Windows Update While Telling Bill Gates to Fix His SoftwarePublished
2024-08-28Nation-StateGhostNet: The Chinese Espionage Network That Compromised 1,295 Computers in 103 Countries and Could Watch Through Your WebcamPublished
2024-08-21MalwareNimda: The Worm That Used Five Propagation Vectors Simultaneously and Became the Internet's Top Threat in 22 MinutesPublished
2024-08-18Nation-StateAPT10 Cloud Hopper: How China Compromised 45 MSPs to Reach Hundreds of Their Clients SimultaneouslyPublished
2024-08-14Nation-StateGeorgia 2008: The First Cyberattacks Synchronized with a Conventional Military InvasionPublished
2024-08-10MalwareSQL Slammer: The 376-Byte Worm That Infected 75,000 Servers in 10 Minutes and Is Still the Fastest Malware EverPublished
2024-08-05Nation-StateThe 2007 Estonian Cyberattacks: The First Nation-State DDoS Campaign and the Birth of NATO Cyber DefencePublished