<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>syscfg - Security Research</title>
    <link>https://syscfg.sh</link>
    <description>Independent security research: incident history, threat actor operations, underground community culture, and technical deep-dives.</description>
    <language>en-us</language>
    <lastBuildDate>Thu, 01 Oct 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://syscfg.sh/feed.xml" rel="self" type="application/rss+xml"/>
    <managingEditor>syscfg</managingEditor>
    <webMaster>syscfg</webMaster>
    <ttl>60</ttl>
    <item>
      <title>The Persistence Layer IR Tools Cannot See: LoJax, CosmicStrand, BlackLotus and What It Takes to Find Firmware-Level Implants</title>
      <link>https://syscfg.sh/research/uefi-firmware-persistence-lojax-cosmicstrand-blacklotus</link>
      <guid isPermaLink="true">https://syscfg.sh/research/uefi-firmware-persistence-lojax-cosmicstrand-blacklotus</guid>
      <description>LoJax in 2018, CosmicStrand in 2022, BlackLotus in 2023. Each one survives an OS reinstall, a disk wipe, and a complete CrowdStrike scan - because none of them live where those tools look. A technical walkthrough of all three cases, what they do to the boot chain, and the three tools that can actually find them: CHIPSEC for SPI flash inspection, UEFITool for firmware image analysis, and TPM PCR attestation for boot integrity measurement. Pairs with the DDRop article as a hardware-trust cluster.</description>
      <pubDate>Thu, 01 Oct 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>uefi</category>
      <category>firmware</category>
      <category>rootkit</category>
      <category>bootkit</category>
      <category>lojax</category>
      <category>cosmicstrand</category>
      <category>blacklotus</category>
      <category>apt28</category>
      <category>secure-boot</category>
      <category>cve-2022-21894</category>
      <category>chipsec</category>
      <category>uefi-tool</category>
      <category>tpm</category>
      <category>pcr-attestation</category>
      <category>incident-response</category>
      <category>detection-engineering</category>
      <category>byovd</category>
      <category>spi-flash</category>
    </item>
    <item>
      <title>Secure Against Whom? The Hardware of Resisting Surveillance, With the Marketing Removed</title>
      <link>https://syscfg.sh/research/going-dark-hardware-surveillance</link>
      <guid isPermaLink="true">https://syscfg.sh/research/going-dark-hardware-surveillance</guid>
      <description>The companion to the Crypto Wars piece: given that the cypherpunks won strong encryption, what does using it in hardware actually look like - and what does each piece of kit not do? A field guide with the marketing removed, built around the only question that matters: secure against whom? Hardware keys, GrapheneOS, Faraday bags, EFF&apos;s Rayhunter IMSI-catcher detector, and the metadata wall every layer hits. Every measure states its limits. Includes an interactive threat-model picker.</description>
      <pubDate>Mon, 28 Sep 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>surveillance</category>
      <category>privacy</category>
      <category>opsec</category>
      <category>threat-model</category>
      <category>grapheneos</category>
      <category>fido2</category>
      <category>yubikey</category>
      <category>faraday-bag</category>
      <category>imsi-catcher</category>
      <category>stingray</category>
      <category>rayhunter</category>
      <category>eff</category>
      <category>metadata</category>
      <category>signal</category>
      <category>hardware</category>
    </item>
    <item>
      <title>When Encryption Was a Weapon: The Cypherpunks, the Crypto Wars, and the Book That Beat the Munitions List</title>
      <link>https://syscfg.sh/research/crypto-wars-cypherpunks</link>
      <guid isPermaLink="true">https://syscfg.sh/research/crypto-wars-cypherpunks</guid>
      <description>For most of the 1990s a strong encryption program was legally a munition, and exporting it was arms trafficking. The people who broke that framing were a mailing list. This is the story of the cypherpunks and the Crypto Wars: Tim May&apos;s manifesto, Zimmermann publishing PGP&apos;s source as a book to make its munition status absurd, Matt Blaze gutting the Clipper chip, and the Bernstein case that held code is speech - before the ruling was quietly withdrawn. Includes an interactive test of what 1990s export law actually classed as a weapon.</description>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>cypherpunks</category>
      <category>crypto-wars</category>
      <category>pgp</category>
      <category>phil-zimmermann</category>
      <category>clipper-chip</category>
      <category>matt-blaze</category>
      <category>bernstein</category>
      <category>tim-may</category>
      <category>eric-hughes</category>
      <category>itar</category>
      <category>encryption</category>
      <category>first-amendment</category>
      <category>surveillance</category>
      <category>privacy</category>
    </item>
    <item>
      <title>An Extortion Group With a Reputation to Protect: CVE-2026-35273, ShinyHunters, and the FBI Advisory They Want Deleted</title>
      <link>https://syscfg.sh/research/shinyhunters-peoplesoft-cve-2026-35273</link>
      <guid isPermaLink="true">https://syscfg.sh/research/shinyhunters-peoplesoft-cve-2026-35273</guid>
      <description>ShinyHunters exploited an unauthenticated RCE in Oracle PeopleSoft against 100-plus organisations, two thirds of them universities, and published the data one day before Oracle shipped a patch. Post-exploitation ran almost entirely on legitimate software: MeshCentral disguised as an Azure service, a bash script spraying SSH credentials, zstd for exfiltration. In September they defaced the FBI&apos;s job portal and claimed 2 TB via a second PeopleSoft zero-day - and demanded no money, only that the FBI delete an advisory warning victims that this group frequently claims to hold data it does not have. An analysis of the documented campaign, the unverified claim, and an extortion business defending its reputation.</description>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>shinyhunters</category>
      <category>unc6240</category>
      <category>cve-2026-35273</category>
      <category>oracle-peoplesoft</category>
      <category>ssrf</category>
      <category>rce</category>
      <category>meshcentral</category>
      <category>sshpass</category>
      <category>lateral-movement</category>
      <category>fbi</category>
      <category>extortion</category>
      <category>defacement</category>
      <category>instructure</category>
      <category>canvas</category>
      <category>education-sector</category>
      <category>zstd</category>
      <category>kev</category>
      <category>detection-engineering</category>
    </item>
    <item>
      <title>Nobody Logged In: How ShinyHunters Emptied Hundreds of Salesforce Tenants Through OAuth Grants Nobody Owned</title>
      <link>https://syscfg.sh/research/shinyhunters-oauth-saas-supply-chain</link>
      <guid isPermaLink="true">https://syscfg.sh/research/shinyhunters-oauth-saas-supply-chain</guid>
      <description>Three times in ten months, ShinyHunters and associated actors took data out of hundreds of Salesforce tenants without signing in to any of them. No password guessed, no MFA answered, no sign-in alert raised at any victim. The queries came through connected applications those organisations had approved. An analysis of why an approved OAuth grant is the one credential in most environments that nobody owns, nobody reviews and nothing watches - with an interactive comparison of which controls actually see each route in.</description>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>shinyhunters</category>
      <category>oauth</category>
      <category>saas</category>
      <category>supply-chain</category>
      <category>salesforce</category>
      <category>salesloft-drift</category>
      <category>gainsight</category>
      <category>klue</category>
      <category>unc6395</category>
      <category>storm-3138</category>
      <category>identity</category>
      <category>token-theft</category>
      <category>detection-engineering</category>
    </item>
    <item>
      <title>From a Bing Search to Domain-Wide Akira in 44 Hours: SEO Poisoning, wbadmin and the Software Already on the Network</title>
      <link>https://syscfg.sh/research/bumblebee-adaptixc2-akira</link>
      <guid isPermaLink="true">https://syscfg.sh/research/bumblebee-adaptixc2-akira</guid>
      <description>An IT administrator searched Bing for ManageEngine OpManager and installed a trojanized MSI that also installed the real software. Forty-four hours later the domain was encrypted and 77 GB was gone. Almost nothing in the chain was exotic: the credential theft used wbadmin, the persistence used RustDesk, and the discovery used four built-in Windows commands. An analysis of The DFIR Report&apos;s June 2026 writeup, with the infrastructure comparison that suggests the delivery chain is a service sold to more than one actor.</description>
      <pubDate>Sat, 19 Sep 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>akira</category>
      <category>bumblebee</category>
      <category>adaptixc2</category>
      <category>ransomware</category>
      <category>seo-poisoning</category>
      <category>dll-sideloading</category>
      <category>living-off-the-land</category>
      <category>wbadmin</category>
      <category>ntds-dit</category>
      <category>rustdesk</category>
      <category>lsassy</category>
      <category>veeam</category>
      <category>dfir</category>
    </item>
    <item>
      <title>$159 of Hardware Breaks Confidential Computing: DDRop, Dropped DDR5 Writes, and Why Encryption Is Not Freshness</title>
      <link>https://syscfg.sh/research/ddrop-ddr5-interposer-confidential-computing</link>
      <guid isPermaLink="true">https://syscfg.sh/research/ddrop-ddr5-interposer-confidential-computing</guid>
      <description>A $159 board sits between a server&apos;s CPU and its DDR5 memory, passes every boot integrity check, then starts silently discarding writes by injecting parity errors. The encryption still works. The attestation still verifies. The CPU reads cryptographically valid data that is simply out of date - because memory encryption protects contents without recording which version is newest. Forged TDX attestation reports, plaintext page copying on SEV-SNP, and the detection channel that falls out for free: every dropped write raises a correctable ECC error nobody is watching.</description>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>ddrop</category>
      <category>badram</category>
      <category>battering-ram</category>
      <category>confidential-computing</category>
      <category>intel-tdx</category>
      <category>sgx</category>
      <category>amd-sev-snp</category>
      <category>ddr5</category>
      <category>interposer</category>
      <category>hardware-attacks</category>
      <category>attestation</category>
      <category>memory-encryption</category>
      <category>ecc</category>
      <category>tee</category>
    </item>
    <item>
      <title>One Bug, Two Official CVSS Scores: CVE-2025-25249, PivotC2, and the 1.7 Points That Decide Whether Anyone Gets Paged</title>
      <link>https://syscfg.sh/research/pivotc2-fortigate-cve-2025-25249</link>
      <guid isPermaLink="true">https://syscfg.sh/research/pivotc2-fortigate-cve-2025-25249</guid>
      <description>NVD scored CVE-2025-25249 at 9.8. Fortinet, the CNA that assigned it, scored it 8.1. The whole gap is one metric - attack complexity - and it decides whether your process treats a heap overflow in an internet-facing FortiGate daemon as an emergency or as routine. By September 2026 SOCRadar had counted more than 30,000 targeted addresses and 178 confirmed PivotC2 implants, which is the empirical answer. Includes a working CVSS 3.1 calculator loaded with both vectors, and what the implant actually takes off the device.</description>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>fortigate</category>
      <category>fortios</category>
      <category>cve-2025-25249</category>
      <category>pivotc2</category>
      <category>cvss</category>
      <category>capwap</category>
      <category>cw-acd</category>
      <category>edge-devices</category>
      <category>vulnerability-management</category>
      <category>tor</category>
      <category>obfs4</category>
      <category>socradar</category>
      <category>patch-management</category>
    </item>
    <item>
      <title>There Is No C2 Server To Block: EtherRAT, TukTuk, and Command and Control Built Entirely on SaaS</title>
      <link>https://syscfg.sh/research/tuktuk-etherrat-gentlemen-saas-c2</link>
      <guid isPermaLink="true">https://syscfg.sh/research/tuktuk-etherrat-gentlemen-saas-c2</guid>
      <description>An intrusion ending in domain-wide Gentlemen ransomware, where the command and control ran over ClickHouse, Supabase, Ably, Dropbox, GitHub Issues and an Arweave dead drop, with configuration read off the Ethereum blockchain. Every channel is a product a company might be paying for, so blocking the C2 means blocking your own vendors. Includes what the researchers actually found behind the widely repeated claim that the framework was AI-generated, and the four-lesson internal curriculum the group wrote for hunting vulnerable drivers.</description>
      <pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>tuktuk</category>
      <category>etherrat</category>
      <category>gentlemen-ransomware</category>
      <category>etherhiding</category>
      <category>ethereum</category>
      <category>clickhouse</category>
      <category>supabase</category>
      <category>ably</category>
      <category>arweave</category>
      <category>byovd</category>
      <category>edr-evasion</category>
      <category>rclone</category>
      <category>gpo</category>
      <category>kerberoasting</category>
      <category>dfir</category>
    </item>
    <item>
      <title>Somebody Read the Site, Then Came Back Every Week: A Month of Targeted Credential Attacks Against This Server&apos;s Own Usernames</title>
      <link>https://syscfg.sh/research/targeted-ssh-recon-campaign</link>
      <guid isPermaLink="true">https://syscfg.sh/research/targeted-ssh-recon-campaign</guid>
      <description>Two usernames exist in this honeypot&apos;s logs that appear in no credential wordlist: syscfg and feed, the site&apos;s handle and its API subdomain. In 1,251,496 events, exactly five addresses ever tried them - each firing one 40 to 88 minute burst on a single day, paced at one attempt every nine seconds, spread across a month. Three of the five trace to one ISP accounting for 0.21% of observed sources. The reconnaissance was targeted; the 147-password wordlist behind it was entirely off the shelf.</description>
      <pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>honeypot</category>
      <category>cowrie</category>
      <category>ssh</category>
      <category>targeted-attack</category>
      <category>credential-attack</category>
      <category>reconnaissance</category>
      <category>opsec</category>
      <category>threat-intelligence</category>
      <category>ioc</category>
      <category>original-research</category>
    </item>
    <item>
      <title>One Key, 511 Hosts: How a Shared SSH Public Key Fingerprints a Botnet That IP Blocklists Cannot See</title>
      <link>https://syscfg.sh/research/ssh-botnet-rsa-key-fingerprint</link>
      <guid isPermaLink="true">https://syscfg.sh/research/ssh-botnet-rsa-key-fingerprint</guid>
      <description>A single RSA public key was implanted 632 times from 511 distinct source IPs across 30 days of honeypot logs. The delivery command was byte-for-byte identical every time. The source addresses span dozens of countries and ASNs, making blocklist-based defense useless - but the key never changes, because rotating it would orphan every host already backdoored. An analysis of what the shared key reveals about botnet topology, the chattr sequence that preceded every implant, and why a public key is a stronger hunt IOC than any IP address in this dataset.</description>
      <pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>honeypot</category>
      <category>cowrie</category>
      <category>ssh</category>
      <category>botnet</category>
      <category>rsa</category>
      <category>ioc</category>
      <category>threat-hunting</category>
      <category>authorized-keys</category>
      <category>chattr</category>
      <category>botnet-fingerprint</category>
      <category>credential-spray</category>
      <category>original-research</category>
      <category>threat-intelligence</category>
    </item>
    <item>
      <title>Two Ways Into the Build: ChainDrop&apos;s npm Worm, XCSSET v40, and Why Valid Provenance Is Not a Defence</title>
      <link>https://syscfg.sh/research/build-step-supply-chain-chaindrop-xcsset</link>
      <guid isPermaLink="true">https://syscfg.sh/research/build-step-supply-chain-chaindrop-xcsset</guid>
      <description>An npm worm in 400+ packages and a macOS infostealer hiding in Xcode projects, four months apart, sharing no code and probably no operator. Both attack the same thing: the moment a developer turns source into software. ChainDrop reads CI secrets out of process memory and publishes genuine SLSA provenance through Sigstore for its own malicious artifact. XCSSET recompiles its loader eight times a day and ages its domains for months. Neither is a bypass - both are security controls working exactly as specified on an input nobody specified for.</description>
      <pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>supply-chain</category>
      <category>chaindrop</category>
      <category>npm</category>
      <category>xcsset</category>
      <category>macos</category>
      <category>xcode</category>
      <category>ci-cd</category>
      <category>sigstore</category>
      <category>slsa</category>
      <category>provenance</category>
      <category>ethereum</category>
      <category>etherhiding</category>
      <category>bun</category>
      <category>chrome-cdp</category>
      <category>credential-theft</category>
    </item>
    <item>
      <title>Testing a Four-Year-Old Botnet Fingerprint: The mdrfckr Campaign&apos;s Published HASSH Is Dead and Its Payload Never Changed</title>
      <link>https://syscfg.sh/research/mdrfckr-hassh-ioc-decay</link>
      <guid isPermaLink="true">https://syscfg.sh/research/mdrfckr-hassh-ioc-decay</guid>
      <description>A HASSH fingerprint published in 2022 for the mdrfckr SSH botnet matched zero of 632 implants in a 2026 honeypot corpus. The campaign now runs libssh 0.9.6, 0.11.1 and 0.12.0, and its newest builds negotiate post-quantum key exchange. The implanted RSA key - 2048-bit, public exponent 37 - has not changed a byte in four years, because rotating it would orphan every host already backdoored. An independent test of someone else&apos;s indicator, and what it says about ranking IOCs by what they cost the adversary to change.</description>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>hassh</category>
      <category>ioc-decay</category>
      <category>mdrfckr</category>
      <category>dota</category>
      <category>ssh</category>
      <category>cowrie</category>
      <category>honeypot</category>
      <category>botnet</category>
      <category>libssh</category>
      <category>detection-engineering</category>
      <category>post-quantum</category>
    </item>
    <item>
      <title>31 Days Inside a Public SSH Honeypot: 1.25 Million Events, Multi-Architecture Malware, and What Automated Attackers Actually Do</title>
      <link>https://syscfg.sh/research/ssh-honeypot-31-days</link>
      <guid isPermaLink="true">https://syscfg.sh/research/ssh-honeypot-31-days</guid>
      <description>A Cowrie SSH honeypot on a Helsinki VPS logged 1,251,496 events across 134,060 sessions in 31 days. Analysis of the raw JSON logs reveals five coordinated addresses whose username lists contained this server&apos;s own identity, a single RSA backdoor key implanted 632 times from 511 distinct IPs via a byte-identical command, active Solana validator hunting, three concurrent Mirai variants, and named multi-architecture malware campaigns. Every number sourced directly from the Cowrie log corpus.</description>
      <pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>honeypot</category>
      <category>cowrie</category>
      <category>ssh</category>
      <category>mitre</category>
      <category>botnet</category>
      <category>mirai</category>
      <category>credential-spray</category>
      <category>threat-intelligence</category>
      <category>malware-analysis</category>
      <category>ioc</category>
    </item>
    <item>
      <title>EchoLeak: Four Defences, Four Bypasses, and What Zero-Click Prompt Injection Says About Filtering an Unconstrained Capability</title>
      <link>https://syscfg.sh/research/echoleak-cve-2025-32711</link>
      <guid isPermaLink="true">https://syscfg.sh/research/echoleak-cve-2025-32711</guid>
      <description>CVE-2025-32711 let an attacker email a target once, never interact again, and have Microsoft 365 Copilot exfiltrate that person&apos;s confidential data when they asked it to summarise their inbox. Microsoft had four separate defences in place - an injection classifier, link redaction, a click requirement and a Content Security Policy - and the exploit walked through all four using alternative Markdown syntax and Microsoft&apos;s own Teams URL-preview endpoint as the proxy. The pattern is more instructive than the trick: every control filtered a representation, none constrained the capability.</description>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>echoleak</category>
      <category>cve-2025-32711</category>
      <category>prompt-injection</category>
      <category>microsoft-365-copilot</category>
      <category>llm-security</category>
      <category>ai-security</category>
      <category>rag</category>
      <category>data-exfiltration</category>
      <category>csp-bypass</category>
      <category>coordinated-disclosure</category>
    </item>
    <item>
      <title>WannaCry and EternalBlue: How the NSA&apos;s Hoarded Exploit Infected 200,000 Machines in 72 Hours</title>
      <link>https://syscfg.sh/research/wannacry-eternalblue</link>
      <guid isPermaLink="true">https://syscfg.sh/research/wannacry-eternalblue</guid>
      <description>In May 2017, a ransomware worm called WannaCry spread to 200,000 machines across 150 countries in three days. It used EternalBlue - a cyberweapon the NSA had developed and stockpiled for years before it was stolen and leaked. A full technical and historical breakdown, with an interactive recreation of the ransom screen.</description>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>wannacry</category>
      <category>eternalblue</category>
      <category>ransomware</category>
      <category>nsa</category>
      <category>shadowbrokers</category>
      <category>smb</category>
      <category>lazarus</category>
    </item>
    <item>
      <title>The Fall of Dread Pirate Roberts: How One Stack Overflow Post Ended Silk Road</title>
      <link>https://syscfg.sh/research/silk-road-dpr-opsec</link>
      <guid isPermaLink="true">https://syscfg.sh/research/silk-road-dpr-opsec</guid>
      <description>Ross Ulbricht built the internet&apos;s first major dark web marketplace, moved $1.2 billion in contraband, and evaded the FBI for two years - until a single post on Stack Overflow under his real name connected everything. A detailed reconstruction of the investigation, the mistakes, and the arrest in a San Francisco library.</description>
      <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>silk-road</category>
      <category>ross-ulbricht</category>
      <category>dpr</category>
      <category>opsec</category>
      <category>darknet</category>
      <category>tor</category>
      <category>bitcoin</category>
    </item>
    <item>
      <title>From Instagram OGs to $100M Heists: The Rise of the SIM Swapping Scene</title>
      <link>https://syscfg.sh/research/sim-swapping-og-scene</link>
      <guid isPermaLink="true">https://syscfg.sh/research/sim-swapping-og-scene</guid>
      <description>It started with stealing Instagram handles. By 2020, the same community of teenagers had compromised Twitter&apos;s internal tools, hijacked 130 celebrity accounts, and stolen hundreds of millions in cryptocurrency. A full history of the SIM swapping scene - from OGUsers to PlugwalkJoe to the most public hack in social media history.</description>
      <pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>sim-swapping</category>
      <category>ogusers</category>
      <category>cryptocurrency</category>
      <category>social-engineering</category>
      <category>telecom</category>
      <category>twitter-hack</category>
    </item>
    <item>
      <title>Operation Bayonet: The Dark Web&apos;s Most Sophisticated Takedown</title>
      <link>https://syscfg.sh/research/operation-bayonet</link>
      <guid isPermaLink="true">https://syscfg.sh/research/operation-bayonet</guid>
      <description>In 2017, law enforcement didn&apos;t just take down the two largest dark web markets - they secretly ran one of them for a month first. The story of how Alexandre Cazes lost AlphaBay to a personal hotmail address, how Dutch police quietly seized Hansa and watched 10,000 users incriminate themselves, and why this was the most methodical takedown the dark web has ever seen.</description>
      <pubDate>Fri, 31 Jul 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>alphabay</category>
      <category>hansa</category>
      <category>darknet</category>
      <category>operation-bayonet</category>
      <category>alexandre-cazes</category>
      <category>dea</category>
      <category>fbi</category>
      <category>opsec</category>
    </item>
    <item>
      <title>OPSEC Hall of Shame: The Mistakes That Ended Careers</title>
      <link>https://syscfg.sh/research/opsec-hall-of-shame</link>
      <guid isPermaLink="true">https://syscfg.sh/research/opsec-hall-of-shame</guid>
      <description>A documented catalogue of operational security failures - from LulzSec&apos;s Sabu logging into IRC without a proxy once, to Pompompurin accidentally typing his own Gmail address in a public post, to the darknet admin who sent support emails from his personal hotmail. Every case study follows the same arc: years of careful tradecraft, undone by a single moment of carelessness.</description>
      <pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>opsec</category>
      <category>arrested</category>
      <category>mistakes</category>
      <category>sabu</category>
      <category>pompompurin</category>
      <category>intelbroker</category>
      <category>cybercrime</category>
    </item>
    <item>
      <title>50 Days of Lulz: The LulzSec Rampage, the Informant, and the Fall</title>
      <link>https://syscfg.sh/research/lulzsec-50-days</link>
      <guid isPermaLink="true">https://syscfg.sh/research/lulzsec-50-days</guid>
      <description>For 50 days in 2011, LulzSec humiliated some of the most powerful institutions on the internet - the CIA, the FBI&apos;s affiliate site, Sony, HBGary Federal - then dissolved. What the public didn&apos;t know was that their leader, Sabu, had already been caught and flipped. A reconstruction of the most chaotic hacking spree of the era and how a single unmasked IRC session ended it.</description>
      <pubDate>Sat, 25 Jul 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>lulzsec</category>
      <category>anonymous</category>
      <category>sabu</category>
      <category>hbgary</category>
      <category>sony</category>
      <category>antisec</category>
      <category>fbi-informant</category>
    </item>
    <item>
      <title>The COM: How Teenagers Became the Most Disruptive Hackers in America</title>
      <link>https://syscfg.sh/research/the-com-scattered-spider</link>
      <guid isPermaLink="true">https://syscfg.sh/research/the-com-scattered-spider</guid>
      <description>From 4chan raids and IRC to OGUsers and Discord, a generation of English-speaking teenagers built a cybercrime ecosystem that took down Microsoft, Nvidia, Uber, MGM Resorts, and Caesars Entertainment. An inside look at &apos;The COM&apos; - the loose network of drama-fuelled young hackers whose preferred attack vector is still a phone call.</description>
      <pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>scattered-spider</category>
      <category>lapsus</category>
      <category>the-com</category>
      <category>mgm</category>
      <category>caesars</category>
      <category>social-engineering</category>
      <category>teenagers</category>
    </item>
    <item>
      <title>The Fappening: Anatomy of a Two-Year Celebrity Phishing Campaign</title>
      <link>https://syscfg.sh/research/fappening-anatomy</link>
      <guid isPermaLink="true">https://syscfg.sh/research/fappening-anatomy</guid>
      <description>One man, working alone for almost two years, built a custom phishing kit that mirrored Apple and Google login pages, sent targeted emails to celebrities, and quietly downloaded hundreds of iCloud backups. The investigation into the 2014 iCloud leak reveals how methodical, patient, and low-tech the most high-profile hack of that decade actually was.</description>
      <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>phishing</category>
      <category>icloud</category>
      <category>celebrity</category>
      <category>social-engineering</category>
      <category>opsec</category>
      <category>ryan-collins</category>
    </item>
    <item>
      <title>ShadowCrew: The Forum That Invented Modern Cybercrime</title>
      <link>https://syscfg.sh/research/shadowcrew-origins</link>
      <guid isPermaLink="true">https://syscfg.sh/research/shadowcrew-origins</guid>
      <description>Before BreachForums, before Nulled, before every combolist forum that followed - there was ShadowCrew. Founded in 2002 by Brett Johnson (later called &apos;The Original Internet Godfather&apos;), it pioneered the structure, the reputation system, and the vendor economy that every dark web marketplace since has copied. In 2004, the Secret Service arrested 33 people in six countries in six hours.</description>
      <pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>shadowcrew</category>
      <category>carding</category>
      <category>darknet</category>
      <category>brett-johnson</category>
      <category>secret-service</category>
      <category>cybercrime-history</category>
    </item>
    <item>
      <title>Stuxnet: The First Cyberweapon That Broke Real Machines</title>
      <link>https://syscfg.sh/research/stuxnet</link>
      <guid isPermaLink="true">https://syscfg.sh/research/stuxnet</guid>
      <description>Operation Olympic Games, joint NSA and Israeli Unit 8200 project, deployed the most sophisticated cyberweapon ever built against Iran&apos;s Natanz enrichment facility. Stuxnet used four zero-days, a Siemens PLC rootkit, and a SCADA spoofing layer to silently destroy 1,000 centrifuges over 18 months while operators watched screens showing normal readings.</description>
      <pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>stuxnet</category>
      <category>iran</category>
      <category>natanz</category>
      <category>siemens</category>
      <category>plc</category>
      <category>zero-day</category>
      <category>nsa</category>
      <category>unit-8200</category>
      <category>olympic-games</category>
    </item>
    <item>
      <title>Mirai: How Three College Students Broke the Internet With Default Passwords</title>
      <link>https://syscfg.sh/research/mirai-botnet</link>
      <guid isPermaLink="true">https://syscfg.sh/research/mirai-botnet</guid>
      <description>In October 2016, a botnet of 600,000 compromised IP cameras and home routers launched the largest DDoS attack in history, taking down Twitter, Netflix, Reddit, and Spotify via a single DNS provider. The authors were three college students who built it to win arguments about Minecraft server hosting.</description>
      <pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>mirai</category>
      <category>botnet</category>
      <category>iot</category>
      <category>ddos</category>
      <category>dyn</category>
      <category>paras-jha</category>
      <category>default-credentials</category>
      <category>telnet</category>
    </item>
    <item>
      <title>NotPetya: The $10 Billion Cyberweapon Disguised as Ransomware</title>
      <link>https://syscfg.sh/research/notpetya</link>
      <guid isPermaLink="true">https://syscfg.sh/research/notpetya</guid>
      <description>On June 27, 2017, Russian military intelligence deployed a cyberweapon through a Ukrainian accounting software update that destroyed $10 billion worth of computer systems globally. NotPetya was not ransomware - the ransom demand was misdirection. The files could not be recovered. A reconstruction of the most destructive cyberattack in history.</description>
      <pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>notpetya</category>
      <category>sandworm</category>
      <category>gru</category>
      <category>russia</category>
      <category>ukraine</category>
      <category>supply-chain</category>
      <category>eternalblue</category>
      <category>mimikatz</category>
      <category>wiper</category>
      <category>maersk</category>
    </item>
    <item>
      <title>Log4Shell: The CVSS 10.0 Vulnerability Hidden Inside Every Java App</title>
      <link>https://syscfg.sh/research/log4shell</link>
      <guid isPermaLink="true">https://syscfg.sh/research/log4shell</guid>
      <description>CVE-2021-44228 received the maximum CVSS score of 10.0 and affected virtually every Java application on the internet. The vulnerability: Log4j evaluated JNDI lookups embedded in log messages, allowing attackers to trigger remote code execution by sending a single string to any logged field. Nation-state actors and ransomware groups were exploiting it within 24 hours of disclosure.</description>
      <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>log4shell</category>
      <category>log4j</category>
      <category>cve-2021-44228</category>
      <category>jndi</category>
      <category>rce</category>
      <category>java</category>
      <category>apache</category>
      <category>supply-chain</category>
    </item>
    <item>
      <title>Colonial Pipeline: The Single Password That Shut Down East Coast Fuel Supply</title>
      <link>https://syscfg.sh/research/colonial-pipeline</link>
      <guid isPermaLink="true">https://syscfg.sh/research/colonial-pipeline</guid>
      <description>DarkSide ransomware group accessed Colonial Pipeline&apos;s network via a single leaked VPN password with no MFA. The resulting six-day shutdown of the US&apos;s largest fuel pipeline caused a national emergency, gas shortages across the East Coast, and a $4.4M ransom. The FBI later recovered $2.3M by seizing DarkSide&apos;s wallet private key.</description>
      <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>colonial-pipeline</category>
      <category>darkside</category>
      <category>ransomware</category>
      <category>raas</category>
      <category>critical-infrastructure</category>
      <category>ics</category>
      <category>mfa</category>
      <category>vpn</category>
    </item>
    <item>
      <title>DNS Security: Cache Poisoning, Nation-State Hijacking, and the Protocol That Never Got Security Right</title>
      <link>https://syscfg.sh/research/dns-security-attacks</link>
      <guid isPermaLink="true">https://syscfg.sh/research/dns-security-attacks</guid>
      <description>DNS was designed in 1983 before security was a requirement. The Kaminsky attack in 2008 demonstrated cache poisoning at scale. Iranian and other state actors have hijacked government domains through registrar compromise and BGP redirection. DNS over HTTPS encrypts queries for privacy but breaks enterprise security monitoring. A comprehensive look at DNS&apos;s structural security failures and the incremental fixes that haven&apos;t quite solved them.</description>
      <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>dns</category>
      <category>dnssec</category>
      <category>cache-poisoning</category>
      <category>kaminsky</category>
      <category>doh</category>
      <category>dns-hijacking</category>
      <category>sea-turtle</category>
      <category>dnspionage</category>
      <category>registrar-attack</category>
    </item>
    <item>
      <title>npm, PyPI, and the Package Manager Attack Surface: How Malicious Code Reaches Millions of Developers</title>
      <link>https://syscfg.sh/research/package-manager-supply-chain</link>
      <guid isPermaLink="true">https://syscfg.sh/research/package-manager-supply-chain</guid>
      <description>From the left-pad incident that brought down thousands of builds to the event-stream Bitcoin theft targeting Copay, the open source package ecosystem has become a primary attack surface. Typosquatting, dependency confusion, and maintainer account takeover campaigns compromise millions of developer machines daily. The xz-utils backdoor proved even trusted packages with years of history aren&apos;t safe. The scale problem has no clean solution.</description>
      <pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>npm</category>
      <category>pypi</category>
      <category>supply-chain</category>
      <category>typosquatting</category>
      <category>dependency-confusion</category>
      <category>event-stream</category>
      <category>left-pad</category>
      <category>slsa</category>
      <category>package-manager</category>
    </item>
    <item>
      <title>Phineas Fisher and the Hacking Team Breach: Hacktivism as Political Direct Action</title>
      <link>https://syscfg.sh/research/phineas-fisher-hacking-team</link>
      <guid isPermaLink="true">https://syscfg.sh/research/phineas-fisher-hacking-team</guid>
      <description>In 2015, a lone operator known as Phineas Fisher breached Hacking Team and released 400GB of internal data - source code, customer lists, zero-days, and communications that exposed the surveillance company&apos;s sales to governments under arms embargoes. They then published a detailed guide explaining exactly how they did it. The third major breach in a pattern of targeted attacks against commercial spyware vendors, conducted as explicit political direct action.</description>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>phineas-fisher</category>
      <category>hacking-team</category>
      <category>finfisher</category>
      <category>gamma-group</category>
      <category>hacktivism</category>
      <category>commercial-spyware</category>
      <category>flash-zero-day</category>
      <category>400gb-dump</category>
    </item>
    <item>
      <title>Mt. Gox to Bybit: A History of Cryptocurrency Exchange Hacks and the $10 Billion Stolen</title>
      <link>https://syscfg.sh/research/crypto-exchange-hacks</link>
      <guid isPermaLink="true">https://syscfg.sh/research/crypto-exchange-hacks</guid>
      <description>From Mt. Gox&apos;s 850,000 Bitcoin in 2014 to the $1.5B Bybit theft in 2025, cryptocurrency exchanges have lost billions in recurring predictable patterns: hot wallet compromises, smart contract exploits, and supply chain attacks on key management infrastructure. The irreversibility of cryptocurrency transactions means every failure is permanent. A comprehensive history of the largest thefts and the structural vulnerabilities that made them possible.</description>
      <pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>mt-gox</category>
      <category>bitfinex</category>
      <category>binance</category>
      <category>ronin</category>
      <category>bybit</category>
      <category>lazarus</category>
      <category>hot-wallet</category>
      <category>transaction-malleability</category>
      <category>defi</category>
      <category>bridge-hack</category>
    </item>
    <item>
      <title>The Cuckoo&apos;s Egg: How a 75-Cent Accounting Error Led to a KGB Spy Hunt in 1986</title>
      <link>https://syscfg.sh/research/cuckoos-egg-clifford-stoll</link>
      <guid isPermaLink="true">https://syscfg.sh/research/cuckoos-egg-clifford-stoll</guid>
      <description>In 1986, Clifford Stoll was tracking a 75-cent accounting discrepancy at Lawrence Berkeley Lab when he discovered a West German hacker systematically raiding US military computers on behalf of the KGB. His ten-month investigation - conducted solo with no legal framework, no interagency coordination, and tools he built from scratch - invented honeypots, intrusion detection, and cyber counterintelligence before those words existed.</description>
      <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>cuckoos-egg</category>
      <category>clifford-stoll</category>
      <category>kGB</category>
      <category>markus-hess</category>
      <category>ARPANET</category>
      <category>honeypot</category>
      <category>incident-response</category>
      <category>cold-war</category>
      <category>berkeley</category>
    </item>
    <item>
      <title>The Juniper Backdoor: How the NSA&apos;s Cryptographic Weakness Was Repurposed by a Foreign Adversary</title>
      <link>https://syscfg.sh/research/juniper-backdoor-dual-ec</link>
      <guid isPermaLink="true">https://syscfg.sh/research/juniper-backdoor-dual-ec</guid>
      <description>In 2015, Juniper Networks discovered unauthorized code in its VPN firmware that had been present since 2012 - a modified Dual EC DRBG constant that could decrypt VPN traffic, and a hardcoded admin password. Investigation revealed the modification appeared to repurpose the NSA&apos;s own cryptographic backdoor mechanism, rekeyed to a different actor&apos;s trap door. The most concrete real-world demonstration that &apos;nobody but us&apos; vulnerabilities don&apos;t stay that way.</description>
      <pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>juniper</category>
      <category>dual-ec-drbg</category>
      <category>nsa</category>
      <category>backdoor</category>
      <category>screenos</category>
      <category>vpn</category>
      <category>nobus</category>
      <category>cryptographic-weakness</category>
      <category>china</category>
    </item>
    <item>
      <title>FinFisher, Hacking Team, Pegasus: Inside the Commercial Spyware Industry That Sells Surveillance to Governments</title>
      <link>https://syscfg.sh/research/commercial-spyware-industry</link>
      <guid isPermaLink="true">https://syscfg.sh/research/commercial-spyware-industry</guid>
      <description>There is a legal industry that sells silent device compromise tools to governments, marketed as &apos;lawful intercept&apos; for law enforcement. FinFisher, Hacking Team&apos;s RCS, and NSO Group&apos;s Pegasus have all been documented targeting journalists, lawyers, dissidents, and opposition politicians alongside criminals. The Hacking Team breach in 2015 exposed the gap between stated vetting and actual practice. Pegasus used zero-click exploits to compromise iPhones with no user interaction.</description>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>pegasus</category>
      <category>nso-group</category>
      <category>finfisher</category>
      <category>hacking-team</category>
      <category>commercial-spyware</category>
      <category>citizen-lab</category>
      <category>zero-click</category>
      <category>lawful-intercept</category>
      <category>surveillance</category>
    </item>
    <item>
      <title>GameOver Zeus: The $100M Banking Trojan, CryptoLocker, and the Cybercriminal Russia Won&apos;t Extradite</title>
      <link>https://syscfg.sh/research/gameover-zeus-bogachev</link>
      <guid isPermaLink="true">https://syscfg.sh/research/gameover-zeus-bogachev</guid>
      <description>Evgeniy Bogachev&apos;s GameOver Zeus infected over 500,000 machines with a peer-to-peer banking trojan that stole $100M+ and delivered the first major ransomware campaign - CryptoLocker - at scale. Operation Tovar disrupted the network in 2014. Bogachev was indicted and the FBI offered a $3M reward. He lives openly on the Russian Black Sea coast. Evidence suggests his infrastructure was simultaneously used for Russian intelligence collection on Ukraine.</description>
      <pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>gameover-zeus</category>
      <category>bogachev</category>
      <category>zeus</category>
      <category>cryptolocker</category>
      <category>p2p-botnet</category>
      <category>banking-trojan</category>
      <category>russia</category>
      <category>operation-tovar</category>
      <category>fbi-reward</category>
    </item>
    <item>
      <title>Yahoo&apos;s 3 Billion Compromised Accounts: The Breach That Changed Corporate Disclosure Law</title>
      <link>https://syscfg.sh/research/yahoo-data-breaches</link>
      <guid isPermaLink="true">https://syscfg.sh/research/yahoo-data-breaches</guid>
      <description>Yahoo suffered two separate breaches - 500 million accounts in 2014, 3 billion in 2013 - and disclosed both during its acquisition by Verizon. Russian FSB officers and criminal associates were indicted. The delayed disclosure cost Yahoo $350M in its acquisition price and led to the first SEC enforcement action against a public company for failing to timely disclose a cybersecurity incident to investors. The credential data is still in use a decade later.</description>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>yahoo</category>
      <category>data-breach</category>
      <category>fsb</category>
      <category>russia</category>
      <category>verizon</category>
      <category>md5</category>
      <category>credential-stuffing</category>
      <category>sec</category>
      <category>m&amp;a</category>
      <category>forged-cookies</category>
    </item>
    <item>
      <title>Tor and the Dark Web: How a Navy Research Project Became the Infrastructure of the Underground</title>
      <link>https://syscfg.sh/research/tor-dark-web-history</link>
      <guid isPermaLink="true">https://syscfg.sh/research/tor-dark-web-history</guid>
      <description>Tor was designed by the US Navy to anonymize government communications - and released publicly because anonymity networks only work with cover traffic. From Naval Research Laboratory to State Department funding to the backbone of global dark web marketplaces, the history of onion routing tracks the internet&apos;s parallel economy. How hidden services work, how they were deanonymized, and why it was usually OPSEC failure rather than cryptographic breaks that brought them down.</description>
      <pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>tor</category>
      <category>dark-web</category>
      <category>onion-routing</category>
      <category>hidden-services</category>
      <category>silk-road</category>
      <category>alphaby</category>
      <category>hansa</category>
      <category>operation-onymous</category>
      <category>blockchain-analysis</category>
    </item>
    <item>
      <title>Kaseya and REvil: The Supply Chain Ransomware Attack That Hit 1,500 Businesses on July 4th Weekend</title>
      <link>https://syscfg.sh/research/kaseya-revil-ransomware</link>
      <guid isPermaLink="true">https://syscfg.sh/research/kaseya-revil-ransomware</guid>
      <description>On July 2, 2021, REvil exploited authentication bypass vulnerabilities in Kaseya VSA - software used by managed service providers to remotely manage client computers - and deployed ransomware through the platform to 1,500 businesses across 17 countries. Coop supermarkets closed 800 stores in Sweden. The FBI held a decryptor for three weeks while conducting operations against REvil. Yaroslav Vasinskyi was later sentenced to 13 years.</description>
      <pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>kaseya</category>
      <category>revil</category>
      <category>ransomware</category>
      <category>msp</category>
      <category>supply-chain</category>
      <category>cve-2021-30116</category>
      <category>vasinskyi</category>
      <category>sweden</category>
      <category>fbi-decryptor</category>
    </item>
    <item>
      <title>MGM vs Caesars: The $100M Casino Hack That Defined the Ransomware Debate</title>
      <link>https://syscfg.sh/research/mgm-caesars-scattered-spider</link>
      <guid isPermaLink="true">https://syscfg.sh/research/mgm-caesars-scattered-spider</guid>
      <description>In September 2023, Scattered Spider compromised both MGM Resorts and Caesars Entertainment using help desk vishing attacks. Caesars paid $15M and kept operating. MGM refused to pay, took systems offline, and lost $100M in disruption as slot machines went dark across Las Vegas. The attacks illustrated the ransomware affiliate model, the English-speaking COM underground&apos;s growing sophistication, and the impossible calculus of ransom payment decisions.</description>
      <pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>scattered-spider</category>
      <category>mgm</category>
      <category>caesars</category>
      <category>alphv</category>
      <category>blackcat</category>
      <category>ransomware</category>
      <category>vishing</category>
      <category>help-desk</category>
      <category>okta</category>
      <category>the-com</category>
    </item>
    <item>
      <title>The Twitter Hack: How a 17-Year-Old Took Over Obama, Biden, and Musk With One Phone Call</title>
      <link>https://syscfg.sh/research/twitter-2020-hack</link>
      <guid isPermaLink="true">https://syscfg.sh/research/twitter-2020-hack</guid>
      <description>On July 15, 2020, a 17-year-old in Tampa, Florida used vishing to convince Twitter employees to hand over internal admin tool credentials, then took over 130 verified accounts including Barack Obama, Joe Biden, Elon Musk, Bill Gates, and Apple. The subsequent Bitcoin scam netted $120,000. What the attackers had access to but chose not to use - private direct messages of every compromised account - was considerably more alarming.</description>
      <pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>twitter</category>
      <category>vishing</category>
      <category>social-engineering</category>
      <category>bitcoin-scam</category>
      <category>graham-clark</category>
      <category>the-com</category>
      <category>admin-tools</category>
      <category>ogusers</category>
    </item>
    <item>
      <title>The RSA SecurID Breach: When Hackers Stole the Keys to 40 Million Two-Factor Tokens</title>
      <link>https://syscfg.sh/research/rsa-securid-breach</link>
      <guid isPermaLink="true">https://syscfg.sh/research/rsa-securid-breach</guid>
      <description>In March 2011, Chinese state-sponsored attackers compromised RSA Security via a phishing email with a Flash zero-day, and stole the seed values underlying 40 million SecurID tokens used by governments and defense contractors worldwide. Two months later, cloned tokens were used to attack Lockheed Martin. The breach established the template for supply chain attacks on security infrastructure itself - and accelerated the industry away from shared-secret authentication.</description>
      <pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>rsa</category>
      <category>securid</category>
      <category>two-factor</category>
      <category>seed-values</category>
      <category>lockheed-martin</category>
      <category>poison-ivy</category>
      <category>apt</category>
      <category>china</category>
      <category>supply-chain</category>
    </item>
    <item>
      <title>The Bangladesh Bank Heist: How Lazarus Group Stole $81 Million Through the SWIFT Network</title>
      <link>https://syscfg.sh/research/bangladesh-bank-swift-heist</link>
      <guid isPermaLink="true">https://syscfg.sh/research/bangladesh-bank-swift-heist</guid>
      <description>On February 4, 2016, North Korea&apos;s Lazarus Group used access to Bangladesh Bank&apos;s SWIFT terminals to submit $951 million in fraudulent transfer requests to the Federal Reserve Bank of New York. $81 million reached accounts in Manila and disappeared into the Philippine casino industry - which was legally exempt from anti-money-laundering requirements. The largest cyber heist in history exposed the systemic vulnerability of a global financial network where trust was not conditional on security standards.</description>
      <pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>bangladesh-bank</category>
      <category>swift</category>
      <category>lazarus</category>
      <category>north-korea</category>
      <category>federal-reserve</category>
      <category>money-laundering</category>
      <category>philippines</category>
      <category>casinos</category>
    </item>
    <item>
      <title>Ashley Madison: The Breach That Weaponized Personal Data Against 37 Million People</title>
      <link>https://syscfg.sh/research/ashley-madison-breach</link>
      <guid isPermaLink="true">https://syscfg.sh/research/ashley-madison-breach</guid>
      <description>In 2015, the Impact Team stole and published the full user database of Ashley Madison - 37 million records including names, addresses, sexual preferences, and GPS coordinates. The breach triggered a mass extortion wave, documented suicides, and revealed that the majority of the platform&apos;s female accounts were company-operated bots. The human cost dwarfed any corporate financial penalty.</description>
      <pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>ashley-madison</category>
      <category>avid-life-media</category>
      <category>impact-team</category>
      <category>extortion</category>
      <category>fake-profiles</category>
      <category>fembots</category>
      <category>data-breach</category>
      <category>privacy</category>
    </item>
    <item>
      <title>Conficker: The 15-Million-Machine Botnet That Did Almost Nothing</title>
      <link>https://syscfg.sh/research/conficker-worm-botnet</link>
      <guid isPermaLink="true">https://syscfg.sh/research/conficker-worm-botnet</guid>
      <description>In 2008, Conficker assembled the largest botnet in history - 9 to 15 million machines - using a zero-day Windows exploit and a domain generation algorithm that made C2 takedown nearly impossible. It triggered the first coordinated public-private industry response, a $250,000 Microsoft bounty, and global media panic about an April 1 activation date. Then it sent a little spam. The botnet&apos;s authors were never identified, and their true purpose was never established.</description>
      <pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>conficker</category>
      <category>botnet</category>
      <category>DGA</category>
      <category>MS08-067</category>
      <category>windows</category>
      <category>p2p</category>
      <category>working-group</category>
      <category>ukraine</category>
    </item>
    <item>
      <title>The Morris Worm: How a Graduate Student&apos;s Experiment Took Down 10% of the Internet in 1988</title>
      <link>https://syscfg.sh/research/morris-worm-1988</link>
      <guid isPermaLink="true">https://syscfg.sh/research/morris-worm-1988</guid>
      <description>On November 2, 1988, Robert Tappan Morris released a self-replicating worm onto the ARPANET that infected 6,000 machines - roughly 10% of the internet - in 24 hours. A design error intended to prevent detection caused runaway replication that crashed systems at MIT, Stanford, and Berkeley. Morris became the first person convicted under the Computer Fraud and Abuse Act. His worm created CERT, the institution of coordinated computer incident response, and demonstrated that networked systems could be weaponized at scale.</description>
      <pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>morris-worm</category>
      <category>1988</category>
      <category>arpanet</category>
      <category>buffer-overflow</category>
      <category>sendmail</category>
      <category>cfaa</category>
      <category>cert</category>
      <category>finger</category>
    </item>
    <item>
      <title>Spectre and Meltdown: The CPU Vulnerabilities That Affected Every Computer Since 1995</title>
      <link>https://syscfg.sh/research/spectre-meltdown-cpu-vulnerabilities</link>
      <guid isPermaLink="true">https://syscfg.sh/research/spectre-meltdown-cpu-vulnerabilities</guid>
      <description>In January 2018, researchers disclosed two classes of CPU vulnerabilities that affected virtually every modern processor. Meltdown let any process read kernel memory. Spectre broke the isolation between programs by exploiting speculative execution. Neither had a complete fix - only mitigations that degraded performance by up to 30%. The story of an architectural flaw baked into two decades of chip design.</description>
      <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>spectre</category>
      <category>meltdown</category>
      <category>cpu</category>
      <category>side-channel</category>
      <category>speculative-execution</category>
      <category>intel</category>
      <category>amd</category>
      <category>arm</category>
      <category>kernel</category>
      <category>kpti</category>
    </item>
    <item>
      <title>LAPSUS$: The Teenage Hackers Who Breached Microsoft, Nvidia, and Okta with a Phone and a Telegram Account</title>
      <link>https://syscfg.sh/research/lapsus-group-extortion</link>
      <guid isPermaLink="true">https://syscfg.sh/research/lapsus-group-extortion</guid>
      <description>In three months, a group of teenagers compromised Microsoft, Nvidia, Samsung, Okta, T-Mobile, and Rockstar Games - leaking source code live on Telegram, holding Q&amp;A sessions with followers, and recruiting insiders at $20,000 per week. Their primary tool was not malware but MFA fatigue, purchased credentials, and an almost theatrical disregard for getting caught. The primary suspect was 16 years old.</description>
      <pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>lapsus</category>
      <category>mfa-fatigue</category>
      <category>sim-swapping</category>
      <category>okta</category>
      <category>nvidia</category>
      <category>microsoft</category>
      <category>rockstar</category>
      <category>the-com</category>
      <category>social-engineering</category>
    </item>
    <item>
      <title>The Equifax Breach: How an Unpatched Server and an Expired Certificate Exposed 147 Million Americans</title>
      <link>https://syscfg.sh/research/equifax-breach-apache-struts</link>
      <guid isPermaLink="true">https://syscfg.sh/research/equifax-breach-apache-struts</guid>
      <description>On the day CVE-2017-5638 was published, someone started exploiting it against Equifax. For 76 days, attackers moved through the network undetected while an expired SSL inspection certificate left monitoring tools blind to encrypted exfiltration. 147 million Social Security numbers, birth dates, and credit histories stolen. Attributed to PLA Unit 54. The story of how one credit bureau&apos;s security failures affected half of America.</description>
      <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
      <author>syscfg</author>
      <category>equifax</category>
      <category>apache-struts</category>
      <category>cve-2017-5638</category>
      <category>pla</category>
      <category>china</category>
      <category>credit-bureau</category>
      <category>ssl-inspection</category>
    </item>
  </channel>
</rss>