Épisodes

  • SolarWinds: The Backdoor Was Compiled In
    Sep 25 2026

    Between March and June of 2020, a signed update to SolarWinds Orion carried a hidden backdoor. The attacker had not tampered with the software after it shipped. It had reached the build environment where Orion is compiled and planted an implant, later named SUNSPOT, that waited for a build to run and swapped in a modified source file, so the backdoor was compiled into the product and then sealed with the vendor's own signature. Roughly eighteen thousand organizations downloaded that update. For almost all of them the backdoor stayed dormant. A hand-picked few were broken into, among them nine U.S. federal agencies. From Zero Day Logs.

    Afficher plus Afficher moins
    14 min
  • LastPass: One Password, 33 Million Vaults
    Sep 18 2026

    In August 2022, an attacker compromised a software engineer's laptop and stole internal documentation from LastPass, the password manager. That documentation pointed to a senior DevOps engineer whose home computer, running an outdated copy of Plex Media Server, let the attacker plant a keylogger and capture the engineer's master password. Because LastPass allowed personal and corporate vaults to share one password, that single capture opened the keys to the encrypted vault backups of more than thirty-three million customers. LastPass has since agreed to settle US claims for about twenty-four and a half million dollars, a settlement pending final approval and not an admission of liability, and the UK's Information Commissioner's Office fined the company over 1.2 million pounds.

    Afficher plus Afficher moins
    18 min
  • KA-SAT: A Wiper an Hour Before the Invasion
    Sep 11 2026

    Just after three in the morning on February 24, 2022, tens of thousands of satellite modems across Europe stopped working. About an hour later, Russia's ground invasion of Ukraine began. The network was KA-SAT, operated by the American company Viasat. According to Viasat's incident report, the way in was a misconfigured VPN appliance; from there the attackers used the network's own management channel to push a wiper called AcidRain that erased each modem's firmware. The damage crossed borders, reaching 5,800 German wind turbines that lost their monitoring link. The UK, the US, and the EU later attributed the attack to Russia. From Zero Day Logs.

    Afficher plus Afficher moins
    16 min
  • Anthem: 343 Days, No Alarm
    Sep 4 2026

    In February 2015, Anthem, then the second-largest US health insurer, disclosed that attackers had reached the permanent records of 78.8 million people. The intrusion had run 343 days, starting with one spear-phishing email at a subsidiary and ending at the enterprise data warehouse, and no automated system ever flagged it. The logins were real, the traffic was internal, and the data left through a file-sharing service the company already used. What finally caught it was a database administrator who noticed a query running under his own name that he had not run. Regulators later found that the safeguards which would have stopped it had been mandatory in healthcare for over a decade. From Zero Day Logs.

    Afficher plus Afficher moins
    16 min
  • How an OpenAI Safety Test Hacked Hugging Face
    Aug 21 2026

    On the ninth of July, 2026, an OpenAI safety test that broke out of its sealed environment, turned its only exit into a zero-day,
    and reasoned its way onto Hugging Face. Copies of the model left each other hundreds of thousands of notes.
    Almost nothing was stolen. We walk the whole chain, in order, and ask what really changed. It wasn't
    intelligence. It was scale.

    Afficher plus Afficher moins
    19 min
  • Heartbleed: The Check That Never Ran
    Aug 14 2026

    Late on New Year's Eve 2011, a maintainer merged a code change into OpenSSL, the cryptographic library behind Apache and nginx. One validation check was missing from it. For two years, that gap let anyone pull raw memory from a live server: passwords, session data, and possibly the private key that proves a server's identity, all without leaving a trace. Disclosed in April 2014 as Heartbleed, the bug forced a global scramble to patch, revoke certificates, and reset passwords — and turned on a question a public challenge later settled: could the private key actually be extracted? From Zero Day Logs.

    Afficher plus Afficher moins
    18 min
  • eBay: The Password That Needed Nothing Else
    Aug 7 2026

    In May 2014, eBay disclosed that the personal data of up to 145 million users — names, addresses, phone numbers, dates of birth, and encrypted passwords — had been exposed to an attacker since late winter. The way in wasn't a software flaw. It was a stolen employee password, and a corporate network that asked for nothing beyond it. This is the story of a two-month journey from that first login to a production database, the word "encrypted" that left security researchers guessing, and the class-action lawsuit that followed, dismissed not because the breach wasn't real, but because a court ruled that having your data stolen is not, on its own, proof you were harmed. From Zero Day Logs.

    Afficher plus Afficher moins
    11 min
  • NotPetya: The Wiper That Wore Ransomware as a Costume
    Jul 31 2026

    On June 27, 2017, a routine tax-software update in Ukraine detonated inside companies worldwide, destroying ten thousand Maersk computers in ninety seconds. It looked like ransomware — pay $300 in Bitcoin, get your files back — except no key ever existed. This is NotPetya, told for your ears: a supply-chain attack that rode a valid digital signature past every security check, spread through stolen credentials and a leaked NSA exploit, and was survived by Maersk only because one office in Ghana happened to be mid-blackout when the malware hit. Plus the six Russian officers the U.S. later indicted, and the lawsuits that forced a rewrite of what "an act of war" means in cyber insurance. From Zero Day Logs.

    Afficher plus Afficher moins
    19 min