The LSCP Newsletter
Cyber criminals rarely focus on attacking one specific target. They usually create a specific approach, validate it, and then attack massively. Every month I pick the strongest current attack wave and illustrate it with an ongoing example of who exactly was hacked, how, and why.
Subscribe by emailThe archive
The newsletter was written for its subscribers, not for search engines, so the archive stays out of print. Every issue is listed below – with its topics from mid-2023 onward, when issues started carrying names. Any issue arrives by email on request, as sent.
2026
- – Royal Visit of Gentlemen through FortiGates
- – Klue Had No Clue
- – Git Guts
- – KelpDAO's Path of Zero Defense
- – TeamPCP Teams Up Around PyPI
- – The Blowing Tragedy of DJI Vacuums
- – Kids' Unhealthy Bonds with Bondu
2025
- – How PornHub Databreach will Reshape the 2026
- – Rake of Oracle
- – Dis Cord: unplugged
- – Flex of Plex
- – Sales Force VS Social Engineering Force
- – Controlled Alteration of DELL
- – Scattered Spider Catched Flies
- – A Virus Fettering of Kettering Health
- – "Based" Coinbase
- – Ma, see mock on Masimo
- – I heard you was hurt, iHeartMedia
- – Yale yelps
- – Dues of Endue
- – Serial Hacks of US Cereal
- – Hey, Oracle, could you predict that?
- – Oi, Look at LUKOIL
- – Leakages in California Cryobank
- – Double Invasion: NTT Com
- – CrossCheck: Checked. Crossed
- – Orange Romania Got Punched
- – Bye-Buy, ByBit
- – Heartless Hack of Heartland Bank
- – GrubHub was grabbed
- – DeepSeek is Deeply Sick
- – Otelier caught it's tail
- – "Wolf Haldenstein" Howls To The Moon
- – Urgency in Argentina
- – You Can't Destroy Rome in One Day: DDoSia attacks Italy
2024
- – Central Subtraction of American Addiction Centers
- – Mass cyberattack on Ukraine's state registers
- – A "trivial" hack of Artivion
- – Sunsetting Short-Message-Service (SMS)
- – Starbucks Loses Bucks
- – International Game Technology: Technical Excellence to Lose
- – Sunsetting of Payment Cards
- – Schneider Electric: Don't Feed the Troll
- – One Point is Enough to Hack OnePoint
- – Gamechanger of Change Healthcare
- – Mission Public Library: Steal Dollars of Ms. Kapusta
- – Backdooring of the Wayback Machine
- – Ward's Cyber War
- – Monday Grime of MoneyGram
- – BingX in being X-ed
- – Indodax In DoS after attacks
- – Oh Toodles! Miska - DIS, Muscka - NEY, Mouska - HACKED
- – Hackers got Dick's
- – Nuts and Bolts of McDonald's Hack Results
- – Google Pixel Got Beaten
- – Mobile Guardian Falls Asleep
- – 300 Small Indian Banks hacked: "This Is NOT Sparta!"
- – Cyber Breach in Columbus
- – Zeroed WazirX
- – aTNT July 4th Fireworks
- – Patelco Credit Union in Pattsituation
- – Hotfix for CVE-2024-6387
- – Federal Reserves Cybersecurity and Evolution
- – You need pills? No you don't. Recah pharma can't distrubute
- – UwU Lend Got Rend
- – Just Kidding: School Fraud in Town of Arlington, MA
- – DMM Bitcoin Exchange Leaked Bitcoins
- – Omnivision overlooked a 0-day
- – No Sun for Nissan
- – JP Morgan Chase is On The Case
- – Did DropBox Sign Drop its Last Sigh?
- – Change Healthcare - Pay a Ransom, Receive a Change
- – Back-tiering of Frontier Communications
- – Whines and Mess in Hotel Swinomish
- – Last Chord of Navalny: Russian Sandwich Wholesale
- – Star Casino Flashed Their PII
- – Fear and Loathing in San Diego: LockBit + drug experience = politics
- – Roku Rolls Credentials
- – Casino Del Sol Playing "Fools"
- – FairWay's Vendor Keeps Security In an UnFair Way
- – FixedFloat Fixes Floats
- – PlayDapp Playing Dumb
- – It's a Long Long Ride: Hyundai Cyber Humiliation
- – AnyDesk for Any Body
- – One Pay-o-near The Cuckoo's Nest
- – Micro hack of Microsoft
- – Did you shed your skin, KAA?
- – Orange España: RIPe me, my friend
2023
- – ESO Solutions: How Backups Saved Christmas
- – GTA 6: Gorgeous Theft of Grand Theft Auto
- – Twinkle, Twinkle, Kyivstar, how I wonder whose you are?
- – UK Nuclear Facility was hacked, but don't worry, they initially lost control eight years ago
- – Material Cybersecurity: Two emergency rooms in New Jersey were put down
- – "The Gem State" Gem Loss: Idaho National Lab lost nuke employees' data
- – CL0P Ransom Strategy Change: from MoveIT to SysAid
- – Marina Bay Sands: Was That Access Control Broken?
- – Seiko Six Rivers Media: Non-Ransom-Driven Hacking
- – Three Anti-Phishing requirements Seiko Group should've implement better
- – Double Trouble: The Repeat Cyber Assault on Henry Schein Healthcare
- – A high-flying level of hacking: Air Europa Airline
- – An "Undefendable" Million Dollar Social Engineering Attack Case: St. Johns County, Florida
- – Pro-Russian Cyber Aggression on Canadian Air Control
- – Protecting the House: Lessons from the MGM and Caesars Cybersecurity Breaches
- – Ready For Action: Paw Patrol Snacks' Website Hack Exposes Kids to Inappropriate Content
- – From Night Mode to Nightmare: Dark Deeds of NightOwl App
- – BlockFI, FTX, and Genesis Crypto Companies Affected by T-Mobile SIM-Swapping Attacks
- – Ransomware Attack on Alberta Dental Service Corporation (ADSC)
- – LockBit Ransomware Attack on Varian Medical Systems
- – Mondee Data Leakage
- – CardioComm's Operations Halted
- – Estée Lauder double incident
- – HCA Healthcare data leakage
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
2022
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title
- – No title