Index live· 1,284 files · 148 editions
ForensicPost

Search the index

48 results
Try
Results for “Method”Newest first
26-0810
File

Six Agencies Warn Gunra Ransomware Runs on Leaked Conti Source Code

Conti’s leaked source is still producing operations four years on, and this one gets in through patched CVEs.

GunraCVE-2024-55591, CVE-2025-24472MultipleMethod
Sev 4TargetMultiple critical infrastructure sectorsActorGunraUSA
26-0802
File

Corpus Audit: 251 of 587 Files Record No Established Entry Route

It does not mean SQL injection is rare. It means the disclosure regime records who was affected and not how.

MethodologyMultipleMethod
Sev 1TargetNot applicableActorUnattributed
26-0729
File

FBI and CISA Warn Water Utilities to Protect Internet-Facing PLCs After Attacks

Post-incident guidance that leads with the exposed device rather than the adversary. For a utility with one engineer, that is the usable document.

UnattributedGuidancePublic sectorMethod
Sev 3TargetWater sector operatorsActorUnattributedUSA
26-0728
File

CI Fortify Guidance Tells Critical Infrastructure Operators to Plan for Isolation

New guidance asks operators to build and test plans for running vital systems disconnected. The assumption underneath it is the story.

UnattributedGuidancePublic sectorMethod
Sev 3TargetCritical infrastructure operatorsActorUnattributed
26-0718
File

Vendor Analysis Maps Three ShinyHunters Attack Paths Into Salesforce Tenants

Three documented routes into the same object. Closing one is not closing the campaign, and the map arrived after the territory.

ShinyHuntersMultiple pathsCloudMethod
Sev 3TargetSalesforce tenantsActorShinyHunters
26-0601
File

Five Years in a Grid Network, and Nothing Was Stolen

Five years of access with no exfiltration objective. Pre-positioning breaks every response method that starts by asking what the intruder wanted.

Volt TyphoonLiving off the landPublic sectorPre-positioning
Sev 5TargetUS critical infrastructureActorVolt TyphoonUSA
26-0530
File

Udemy Breach Exposed 1.4 Million Addresses and Instructor Payout Details

1.4 million addresses, and instructor payout methods. A card can be reissued; a bank account configured to receive money cannot.

ShinyHuntersUnder reviewEducationSaaS
Sev 3TargetUdemyActorShinyHunters
26-0428
File

Not a Breach: Half a Million Lines Published by Mistake

No attacker, no intrusion, and half a million lines public anyway. Registry publication is a one-way door.

Internal errorMisconfigured publicationCloudMethod
Sev 2TargetAnthropicActorInternal error
26-0419
File

All Fifty US States Now Impose Breach Notification Duties on a Single Incident

Not one obligation with fifty deadlines — fifty obligations that overlap. It explains why affected counts keep climbing.

UnattributedRegulatoryMultipleMethod
Sev 3TargetUS breach notification regimeActorUnattributedUSA
26-0415
File

UK Retail Attacks Classified as a Category 2 Systemic Event

A hurricane-style category applied to a cyber event. Severity is a property of the victim and its coupling, not of the attack.

UnattributedMethodologyMultipleMethod
Sev 3TargetIncident severity classificationActorUnattributedUnited Kingdom
26-0403
File

US Public Companies Must Disclose Material Cyber Incidents Within Four Days

Four business days from a materiality determination the company itself makes. The clock and the investigation run on incompatible timescales.

UnattributedDisclosure regimeFinanceMethod
Sev 3TargetUS public companiesActorUnattributedUSA
26-0323
File

Coordinated Disclosure Breaks Down at Tens of Thousands of Findings

A deadline is an incentive when meeting it is possible. At this volume it becomes a countdown to publishing defects nobody has fixed.

UnattributedProcessCloudMethod
Sev 3TargetDisclosure governanceActorUnattributed
26-0315
File

The Same Capability, Pointed the Other Way

A backup does not help an attacker. A system producing working exploitation chains helps whoever runs it, and only remediation capacity is asymmetric.

MultipleDual useCloudMethod
Sev 4TargetVulnerability research capabilityActorMultiple
26-0307
File

Thousands of Unfixed Findings Publish With No Party Accountable for the Aggregate

Every party manages its piece correctly and nobody owns the total. The number that would settle the argument is not being published.

UnattributedCoordination failureCloudMethod
Sev 4TargetDisclosure ecosystemActorUnattributed
26-0220
File

A Political Name Is a Claim, Not a Finding

An ideological name requires no capability and no conviction. It buys coverage, and it redirects attention toward a motive that may not exist.

MultipleMethodologyMultipleAttribution
Sev 3TargetAttribution practiceActorMultiple
26-0105
File

The Regulator Told Carriers to Make It Harder

The duty sits with the originating carrier because nobody else can act. It pushes directly against portability rules written by the same regulator.

UnattributedRegulatoryTelecomMethod
Sev 3TargetWireless carriersActorUnattributed
25-1226b
File

Half of 2025 Extortion Involved No Encryption, so Containment Metrics Missed It

A containment rate defined against encryption improves partly because encryption is becoming less common.

MultipleMultipleMethod
Sev 3TargetContainment measurementActorMultiple
25-1207
File

An OAuth Grant Persists Until Somebody Removes It

The failure mode of leaving a grant in place is invisible. The failure mode of removing one is an outage with your name on it.

MultipleDurable credentialsCloudMethod
Sev 4TargetSaaS authorisationsActorMultiple
25-1107
File

Nevada Published After-Action Reports Almost No Other Public Body Does

The litigation mechanism this corpus calls the fastest accountability route suppresses the most useful output an incident can produce.

Public sectorMethod
Sev 2TargetPublic-sector disclosure practiceActorUnattributedUSA
25-1026
File

Princeton Detected and Ejected Attackers Within a Day

Twenty-four hours is not an improvement on 102 days. It is a different regime.

UnattributedVoice phishingEducationMethod
Sev 3TargetPrinceton UniversityActorUnattributed
25-1022
File

Retail, Insurance, Aviation and Universities All Fell to the Same Phone Call

There is no packet to inspect and no domain to block. The output of the call is a legitimate action by an authorised person.

MultipleVoice phishingMultipleMethod
Sev 5TargetMultiple sectorsActorMultiple
25-1011b
File

Self-service Moved the Identity Boundary Onto the Employee

Self-service is not a convenience feature with a security cost. It is a decision about who holds authority.

MultipleDelegated authority abuseMultipleMethod
Sev 4TargetSelf-service estatesActorMultiple
25-0925
File

ENISA Confirmed European Airport Disruption as Ransomware Days Later

A regulator saying “this is ransomware, we don’t yet know by whom” on day two serves everybody better than a complete account on day thirty.

UnattributedGovernanceLogisticsMethod
Sev 3TargetCross-border incident classificationActorUnattributed
25-0924
File

Six Files Exist Because Nevada Published an After-Action Report

Nevada is not a more instructive incident than the other 398. It is a better documented one.

Public sectorMethod
Sev 2TargetIncident disclosure practiceActorUnattributedUSA
25-0923
File

One Technique, One Platform, Several Hundred Companies

What concentrated was not the data but the method. Every tenant presents the same consent screen and the same vocabulary for a caller to use.

ShinyHuntersConsent phishingCloudExtortion
Sev 4TargetSaaS platform tenantsActorShinyHunters
25-0921b
File

The Integrity Failure Nobody in This Corpus Has Recorded

Stolen data eventually appears. Unavailable data is noticed immediately. Altered data continues to be used.

MultipleMultipleMethod
Sev 4TargetIntegrity failuresActorMultiple
25-0901
File

A Token Crossing Three Vendors Belonged Operationally to Nobody

Platform, vendor and customer each secured what they controlled. The token that crossed all three belonged operationally to nobody.

UnattributedShared responsibility gapCloudMethod
Sev 4TargetSaaS integration modelActorUnattributed
25-0820
File

Salesloft Intrusion Began in March and Stayed Dormant Until August

Five months quiet, ten days of theft. A single dwell-time figure conflates the two, and organisations optimise against the wrong phase.

UNC6395Delayed exploitationCloudMethod
Sev 4TargetIncident response practiceActorUNC6395
25-0802
File

Saint Paul Shut Its Whole Network to Evict the Attacker

The only action in this database that produces a certain answer to “are they still in?”

UnattributedPublic sectorMethod
Sev 4TargetCity of Saint PaulActorUnattributed
25-0723
File

ToolShell Stole SharePoint Machine Keys That Survived the Patch

Correctly patched, correctly configured, reporting green, and serving an attacker. Patch coverage cannot see the difference.

MultipleStolen key materialCloudMethod
Sev 5TargetOn-premises SharePoint estatesActorMultiple
25-0625
File

The Authentication That Was Left in Place

An authentication estate is only as strong as its weakest enabled option — and disabling produces an outage with a name attached.

Scattered SpiderLegacy authenticationAviationMethod
Sev 4TargetEnterprise authentication estatesActorScattered Spider
25-0604b
File

Remote Management, for the Sixth Time

The customer-facing application gets the security programme. The thing that administers it does not — and it is more powerful.

MultipleVariousMultipleMethod
Sev 5TargetManagement plane estatesActorMultiple
25-0602b
File

They Looked at the Customer List Before Deciding Anything

The customers were not incidentally exposed. They were surveyed and picked.

DragonForceRMM platform abuseCloudMethod
Sev 4TargetMSP customer estatesActorDragonForce
25-0527
File

Two Leaked Ransomware Operations Disagree on Pricing, Geography and Scale

A second sample that confirmed the first would have been more satisfying and much less informative.

MultipleMultipleMethod
Sev 2TargetNot applicableActorMultiple
25-0518
File

Nevada Intrusion Began With a Poisoned Search Result for an Admin Tool

The employee did go looking for the official site. The search platform put something else first.

UnattributedSearch engine poisoningPublic sectorMethod
Sev 4TargetIT personnelActorUnattributedUSA
25-0503
File

The Agent Is Authorised as You, and Nobody Asked Whether It Should Be

The system correctly identifies who the request is from. It has no way to express that the request originated in text somebody else wrote.

MultiplePrompt injectionCloudMethod
Sev 4TargetAgent authorisation modelsActorMultiple
25-0421b
File

Compromised Credentials Led the Root Causes at 41%, Against 22% for Exploits

The corpus has been over-weighting the minority route, because a named CVE generates documentation and a stolen password does not.

MultipleValid credentialsMultipleMethod
Sev 4TargetIncident response caseloadActorMultiple
25-0311
File

The Consent Screen Asks a Question Nobody Can Answer

A control that is correct 999 times out of 1,000 teaches people to stop reading it. That is not user failure.

MultipleConsent phishingCloudMethod
Sev 3TargetSaaS consent modelsActorMultiple
25-0226
File

The Black Basta Archive Is the Best Primary Source Here and a Sample of One

The most sensitive coordination in any organisation is the least likely to be typed. The archive is a survivorship sample of itself.

Black BastaMultipleMethod
Sev 2TargetNot applicableActorBlack Basta
25-0224
File

A Language Model Cannot Distinguish Code From Content

Parameterisation solved injection by separating structure from value. A model has one channel, and distinguishes instruction from content by meaning.

MultiplePrompt injectionCloudMethod
Sev 4TargetLanguage model systemsActorMultiple
25-0222
File

A Researcher Named Him. This Desk Will Not

Applying the rule to a ransomware leader is the case that tests whether it is a rule or a preference. If it only holds for sympathetic subjects it is not a rule.

Black BastaCriminalMethod
Sev 2TargetNot applicableActorBlack Basta
24-1010
File

Security Firm Assessed Star Health Executive-Involvement Material as Unproven

Authentic data does not authenticate the story told about it. The records check out while the account does not.

InsuranceMethod
Sev 3TargetStar Health and Allied InsuranceActorUnattributedIndia
24-0317
File

Fujitsu Found Malware That Copied Files and Was Not Ransomware

Ransomware has to announce itself. Malware that only copies succeeds by staying unremarkable.

UnattributedTechnologyMethod
Sev 3TargetFujitsuActorUnattributedJapan
23-1110
File

LockBit Published 43GB From Boeing, Revealing the Citrix Bleed Entry Route

A dump is chosen for extortion value, not evidence. This one disclosed its own method.

LockBitCVE-2023-4966 — Citrix BleedManufacturingAftermath
Sev 4TargetBoeingActorLockBitUSA
22-0705
File

Marriott Says Social Engineering of One Employee Exposed 20GB and About 400 People

What differed from the largest files here was not the method. It was whose desk it was.

UnattributedSocial engineeringHospitalityHospitality
Sev 2TargetMarriott InternationalActorUnattributedUSA
22-0301
File

One Plastic-Parts Supplier Stopped Fourteen Toyota Plants

Inventory is waste, so nothing is spare. That is the method working, and it is why one supplier stopped everything.

UnattributedManufacturingSupply chain
Sev 4TargetToyota Motor CorporationActorUnattributedJapan
STD-02
Standard

Grading and severity standard

How a file opens, how it closes, and why we never grade on ransom size.

MethodologySeverityGrading
Method
STD-05
Standard

Anonymous sourcing policy

When we grant anonymity, what we promise, and what we never withhold.

MethodologyEthicsSourcing
Method
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging