Longo.org Cyber History CalendarCanonical source dataset for the Longo.org Cyber History Calendar.2026-09-26133bug#DC2626shield-exclamation#EA580Ctriangle-exclamation#2563EBcrosshairs#7C3AEDlink#0F766Escale-balanced#B7791Findustry#0E7490key#4F46E5globe#0369A1star#15803D1983-11-10Fred Cohen virus demonstrationmilestoneFred Cohen demonstrated self-replicating code during academic security research, helping formalize the modern computer-virus concept.It helped turn malicious self-replication into a defined computer-security problem.star#15803Dtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Fred_Cohen1986-01Brain boot-sector virusmalwareBrain spread through infected floppy-disk boot sectors and is widely cited as the first IBM PC-compatible virus to circulate broadly.It marks malware's transition from research curiosity to something that could spread through ordinary computer use.bug#DC2626trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Brain_(computer_virus)1988-11-02Morris WormmalwareThe Morris Worm spread rapidly across the early Internet, exploiting multiple weaknesses and affecting thousands of systems.It became a foundational Internet security incident and helped drive organized incident-response capability.bug#DC2626truereviewed2026-09-26https://www.fbi.gov/history/famous-cases/morris-wormhttps://en.wikipedia.org/wiki/Morris_worm1988-11-17CERT Coordination Center establishedmilestoneDARPA funded creation of the CERT Coordination Center at Carnegie Mellon after the Morris Worm.Modern incident coordination and vulnerability-response practices trace directly to needs exposed by early Internet-wide incidents.star#15803Dtruereviewed2026-09-26https://www.sei.cmu.edu/about/divisions/cert/index.cfmhttps://en.wikipedia.org/wiki/CERT_Coordination_Center1989-12AIDS Trojan / PC CyborgmalwareThe AIDS Trojan was distributed on floppy disks, hid directories, encrypted filenames, and demanded payment by postal mail.Often cited as the first ransomware, it proves the extortion model predates cryptocurrency by decades.bug#DC2626truereviewed2026-09-26https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/aids-trojanhttps://en.wikipedia.org/wiki/PC_Cyborg1990-06UK Computer Misuse ActgovernanceThe United Kingdom enacted the Computer Misuse Act, creating criminal offenses for unauthorized access and related computer misuse.It became a foundational cybercrime statute and still shapes debates over authorization and security research.scale-balanced#B7791Ftrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Computer_Misuse_Act_19901993-07First DEF CONmilestoneThe first DEF CON brought hackers, researchers, and security practitioners together in Las Vegas.DEF CON became one of the most influential forums for practical security research and hacker culture.star#15803Dtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/DEF_CON1995-02SSL 2.0 era beginsinternetNetscape introduced SSL to protect web communications and support secure commercial use of the Internet.Encrypted web transport became a basic expectation for online trust, despite weaknesses in early versions.globe#0369A1trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Transport_Layer_Security1998-08-03Back Orifice releasedmalwareCult of the Dead Cow released Back Orifice, a remote-administration tool that could covertly control Windows systems.It popularized the concept of remote-access trojans and abuse of legitimate administration functions.bug#DC2626trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Back_Orifice1999-03-26MelissamalwareMelissa spread through infected Word documents and Outlook address books, disrupting enterprise mail systems.Attackers still win by abusing trust, familiar file formats, and legitimate communication channels.bug#DC2626truereviewed2026-09-26https://www.fbi.gov/news/stories/melissa-virus-20th-anniversary-032519https://en.wikipedia.org/wiki/Melissa_(computer_virus)1999-04-26CIH / Chernobyl virusmalwareCIH overwrote hard-drive data and, on some systems, flash BIOS content when it activated.It is an early example of malware designed for destructive impact beyond nuisance or propagation.bug#DC2626truereviewed2026-09-26https://www.sei.cmu.edu/documents/520/1999_019_001_496442.pdfhttps://en.wikipedia.org/wiki/CIH_(computer_virus)1999-09CVE initiative launchedmilestoneMITRE launched Common Vulnerabilities and Exposures to give publicly known vulnerabilities standardized identifiers.CVE created a shared language for vulnerability management across vendors, scanners, advisories, and defenders.star#15803Dtruereviewed2026-09-26https://www.cve.org/About/Historyhttps://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures2000-02Major Internet DDoS attacksinternetDistributed denial-of-service attacks disrupted major Internet properties including Yahoo, Amazon, CNN, and eBay.They demonstrated that even major online services could be overwhelmed through coordinated abuse of compromised systems.globe#0369A1trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/MafiaBoy2000-05-04ILOVEYOU / Love Letter wormmalwareThe Love Letter worm spread through a malicious Visual Basic Script attachment and automated forwarding.It combined human psychology with automated propagation, a pattern still visible in modern phishing and malware delivery.bug#DC2626truereviewed2026-09-26https://www.sei.cmu.edu/documents/507/2000_019_001_496188.pdfhttps://en.wikipedia.org/wiki/ILOVEYOU2001-02-12Anna Kournikova wormmalwareA social-engineering worm disguised as an image of tennis player Anna Kournikova spread widely through email.Compelling lures and trusted communication channels remain durable malware-delivery techniques.bug#DC2626trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Anna_Kournikova_(computer_virus)2001-07-19Code RedmalwareCode Red exploited a vulnerability in Microsoft IIS and infected hundreds of thousands of Internet-facing systems.Self-propagating attacks against exposed infrastructure can move faster than human remediation processes.bug#DC2626truereviewed2026-09-26https://news.microsoft.com/source/2001/07/30/government-and-industry-groups-warn-code-red-internet-worm-ready-for-serious-strike-urge-preventative-measures/https://en.wikipedia.org/wiki/Code_Red_(computer_worm)2001-09-18NimdamalwareNimda spread through email, network shares, compromised websites, vulnerable IIS servers, and earlier backdoors.It demonstrated the danger of combining multiple propagation vectors into one campaign.bug#DC2626truereviewed2026-09-26https://seclists.org/cert/2001/22https://en.wikipedia.org/wiki/Nimda2002-04Klez worm surgemalwareKlez became a widespread email worm, spoofing sender addresses and distributing infected attachments.Sender spoofing and trusted-channel abuse remain basic ingredients of modern social engineering.bug#DC2626trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Klez2003-01-25SQL SlammermalwareSlammer exploited a previously patched SQL Server flaw and caused a dramatic global traffic spike.It remains a classic example of how quickly a worm can weaponize a known vulnerability when patching lags.bug#DC2626truereviewed2026-09-26https://news.microsoft.com/source/2003/01/25/microsoft-statement-on-the-slammer-worm-attack/https://en.wikipedia.org/wiki/SQL_Slammer2003-08-11Blaster wormmalwareBlaster exploited a previously patched Windows RPC vulnerability and scanned continuously for additional vulnerable hosts.It illustrates the persistent gap between patch availability and actual remediation.bug#DC2626truereviewed2026-09-26https://learn.microsoft.com/en-us/troubleshoot/windows-server/security-and-malware/blaster-worm-virus-alerthttps://en.wikipedia.org/wiki/Blaster_(computer_worm)2003-08-18Sobig.FmalwareSobig.F spread through email at enormous scale and generated significant mail disruption.Mass-mailing malware showed how compromised endpoints could become infrastructure for large-scale abuse.bug#DC2626trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Sobig2004-01-26MydoommalwareMydoom spread through email and peer-to-peer networks, opened a backdoor, and launched denial-of-service activity.Compromised endpoints quickly became infrastructure for further attacks, a pattern still seen in botnets.bug#DC2626truereviewed2026-09-26https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Win32%2FMydoomhttps://en.wikipedia.org/wiki/Mydoom2004-05-01SassermalwareSasser exploited the Windows LSASS vulnerability and could propagate without a user opening an attachment.It reinforced the risk of rapid exploitation following vulnerability disclosure.bug#DC2626truereviewed2026-09-26https://news.microsoft.com/source/2004/05/02/microsoft-joins-law-enforcement-to-track-perpetrators-of-emerging-worm-attacks-against-computer-users/https://en.wikipedia.org/wiki/Sasser_(computer_worm)2004-12PCI DSS 1.0governanceMajor payment-card brands created the first Payment Card Industry Data Security Standard.PCI DSS became one of the most influential industry security compliance baselines.scale-balanced#B7791Ftruereviewed2026-09-26https://www.pcisecuritystandards.org/about_us/https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard2005-08-14Zotob wormmalwareZotob exploited a recently disclosed Windows Plug and Play vulnerability and disrupted corporate and media networks.It showed how quickly exploit code can follow a patch and why emergency vulnerability management matters.bug#DC2626trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Zotob2006-01WMF vulnerability crisisvulnerabilityA Windows Metafile vulnerability enabled drive-by exploitation through malicious images and triggered an out-of-cycle security update.Content-parsing flaws can create code-execution paths through routine web browsing.triangle-exclamation#2563EBtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Windows_Metafile_vulnerability2007-01-17TJX breach disclosedincidentTJX disclosed unauthorized access affecting payment-card and customer data across its retail operations.The breach became an early large-scale example of wireless security, card-data, and third-party risk failures.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/TJX_Companies2007-04-27Estonia cyberattacks beginnation_stateEstonian government, banking, media, and other online services experienced sustained disruptive cyber activity amid political tensions.The attacks became a landmark case in national cyber defense, resilience, and geopolitical cyber disruption.crosshairs#7C3AEDtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/2007_cyberattacks_on_Estonia2008-07-08Kaminsky DNS flaw disclosedvulnerabilityDan Kaminsky disclosed a fundamental DNS cache-poisoning weakness after a coordinated multi-vendor patch effort.The episode showed the systemic risk of flaws in core Internet infrastructure and the value of coordinated disclosure.triangle-exclamation#2563EBtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Dan_Kaminsky2008-10-23MS08-067 emergency patchvulnerabilityMicrosoft issued an out-of-band critical update for a remotely exploitable Windows Server service vulnerability.The flaw was later exploited by Conficker and remains a classic emergency-patching case.triangle-exclamation#2563EBtruereviewed2026-09-26https://learn.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-067https://en.wikipedia.org/wiki/MS08-0672008-11-21Conficker discoveredmalwareConficker exploited the Windows Server service vulnerability addressed by MS08-067 and added multiple propagation techniques.It showed how unpatched systems, weak credentials, removable media, and shares can combine into durable malware spread.bug#DC2626truereviewed2026-09-26https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Win32%2FConfickerhttps://en.wikipedia.org/wiki/Conficker2008-12Heartland Payment Systems breach discoveredincidentHeartland discovered a major payment-card breach involving malware in transaction-processing systems.The case became an important milestone in payment-security accountability and processor risk.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Heartland_Payment_Systems2009-07-04U.S. and South Korea DDoS attacksnation_stateGovernment, financial, and media websites in the United States and South Korea were targeted by coordinated denial-of-service attacks.The campaign reinforced the use of botnets for politically significant disruption and the difficulty of attribution.crosshairs#7C3AEDtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/2009_cyberattacks_against_South_Korea_and_the_United_States2010-01-12Operation Aurora disclosednation_stateGoogle disclosed a sophisticated targeted intrusion that stole intellectual property and affected numerous large companies.Aurora was a watershed moment in public corporate disclosure of nation-state activity.crosshairs#7C3AEDtruereviewed2026-09-26https://googleblog.blogspot.com/2010/01/new-approach-to-china.htmlhttps://en.wikipedia.org/wiki/Operation_Aurora2010-06-17Stuxnet first identifiedcritical_infrastructureSecurity researchers identified malware later shown to target specific industrial-control environments.Its discovery marked a turning point in awareness of cyber weapons designed to manipulate physical processes.industry#0E7490trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Stuxnet2010-09-29ICS-CERT Stuxnet advisorycritical_infrastructureICS-CERT documented Stuxnet targeting Siemens industrial-control software and using multiple advanced propagation techniques.Stuxnet permanently changed the conversation around cyber-physical risk.industry#0E7490truereviewed2026-09-26https://www.cisa.gov/uscert/ics/advisories/ICSA-10-272-01https://en.wikipedia.org/wiki/Stuxnet2011-03-17RSA SecurID breach disclosedidentityRSA disclosed an advanced persistent threat and warned that information related to SecurID products had been extracted.Security controls with privileged trust relationships are strategic targets in their own right.key#4F46E5truereviewed2026-09-26https://www.sec.gov/Archives/edgar/data/790070/000119312511070159/d8k.htmhttps://en.wikipedia.org/wiki/RSA_SecurID2011-03-23Comodo certificate compromiseidentityA certificate-authority reseller account was compromised and used to issue fraudulent certificates for major online services.Web trust depends on the operational security of certificate-issuance infrastructure, not cryptography alone.key#4F46E5trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Comodo_Group#Certificate_hacking2011-04-26PlayStation Network breach disclosedincidentSony disclosed a major compromise of PlayStation Network and Qriocity user data after taking services offline.The incident highlighted large-scale consumer identity exposure and the operational cost of prolonged outages.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/2011_PlayStation_Network_outage2011-08-29DigiNotar fraudulent certificates exposedidentityFraudulent certificates issued after compromise of DigiNotar were discovered, ultimately destroying trust in the certificate authority.Compromise of one PKI trust anchor can create ecosystem-wide consequences.key#4F46E5trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/DigiNotar2012-05-28Flame malware revealednation_stateResearchers disclosed Flame, a sophisticated espionage platform used primarily in the Middle East.Flame illustrated the growing complexity and modularity of state-aligned cyber espionage tooling.crosshairs#7C3AEDtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Flame_(malware)2012-06-06LinkedIn password breachincidentMillions of hashed LinkedIn passwords were posted online following a breach.The incident reinforced the importance of strong password hashing, unique credentials, and resistance to credential reuse.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/2012_LinkedIn_hack2012-08-15Shamoon attacks Saudi Aramcocritical_infrastructureShamoon was used in a destructive attack that wiped large numbers of Saudi Aramco workstations.The attack demonstrated the business impact of destructive malware and the importance of segmentation and recovery.industry#0E7490trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Shamoon2013-02-19Mandiant APT1 reportnation_stateMandiant published a detailed report linking a large cyber-espionage campaign to a unit of China's People's Liberation Army.The report helped normalize evidence-based public attribution of state-sponsored cyber operations.crosshairs#7C3AEDtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/PLA_Unit_613982013-03-20DarkSeoul attacksnation_stateCyberattacks disrupted major South Korean banks and broadcasters, wiping systems and affecting operations.The incident showed how destructive malware can be used for national-level disruption.crosshairs#7C3AEDtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/2013_South_Korea_cyberattack2013-10-03Adobe breach disclosedincidentAdobe disclosed an intrusion involving customer information and source code.The breach illustrated the value attackers place on both identity data and proprietary software source code.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Adobe_Inc.#Security_breach2013-12-19Target breach announcedincidentTarget confirmed unauthorized access to payment-card data affecting tens of millions of accounts.The breach became a landmark example of third-party access risk, point-of-sale compromise, and executive accountability.shield-exclamation#EA580Ctruereviewed2026-09-26https://corporate.target.com/press/release/2013/12/target-confirms-unauthorized-access-to-payment-card-data-in-u-s-storeshttps://en.wikipedia.org/wiki/2013_Target_data_breach2014-02-12NIST Cybersecurity Framework 1.0governanceNIST released the first Framework for Improving Critical Infrastructure Cybersecurity.The Framework created a common risk-based language for cybersecurity outcomes and executive communication.scale-balanced#B7791Ftruereviewed2026-09-26https://www.nist.gov/news-events/news/2014/02/nist-releases-cybersecurity-framework-version-10https://en.wikipedia.org/wiki/NIST_Cybersecurity_Framework2014-04-07HeartbleedvulnerabilityHeartbleed exposed a flaw in OpenSSL heartbeat handling that allowed remote attackers to read portions of process memory.It showed how one defect in a ubiquitous security library can create global risk and require key rotation beyond patching.triangle-exclamation#2563EBtruereviewed2026-09-26https://nvd.nist.gov/vuln/detail/CVE-2014-0160https://en.wikipedia.org/wiki/Heartbleed2014-09-08Home Depot breach disclosedincidentHome Depot disclosed a payment-card breach involving malware on point-of-sale systems.Retail breaches reinforced the need for segmentation, payment-environment hardening, and third-party access controls.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Home_Depot#Data_breach2014-09-24ShellshockvulnerabilityShellshock allowed arbitrary command execution through crafted environment variables processed by GNU Bash.It demonstrated the systemic risk created when foundational components are embedded across enormous software estates.triangle-exclamation#2563EBtruereviewed2026-09-26https://nvd.nist.gov/vuln/detail/CVE-2014-6271https://en.wikipedia.org/wiki/Shellshock_(software_bug)2014-10-02JPMorgan Chase breach disclosedincidentJPMorgan Chase disclosed a major intrusion affecting contact information associated with tens of millions of households and small businesses.The incident underscored the scale and attractiveness of identity data held by financial institutions.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/2014_JPMorgan_Chase_data_breach2014-10-14POODLE disclosedvulnerabilityResearchers disclosed a weakness in SSL 3.0 that could allow recovery of plaintext from encrypted connections.Legacy compatibility can preserve attack paths long after stronger replacements exist.triangle-exclamation#2563EBtruereviewed2026-09-26https://security.googleblog.com/2014/10/this-poodle-bites-exploiting-ssl-30.htmlhttps://en.wikipedia.org/wiki/POODLE2014-11-24Sony Pictures destructive attackincidentSony Pictures suffered a destructive intrusion involving malware, stolen data, and major operational disruption.The attack showed how theft, coercion, public disclosure, and destruction can be combined in one campaign.shield-exclamation#EA580Ctruereviewed2026-09-26https://www.fbi.gov/news/press-releases/update-on-sony-investigationhttps://en.wikipedia.org/wiki/Sony_Pictures_hack2015-02-04Anthem breach disclosedincidentAnthem disclosed unauthorized access to a database containing information on current and former members and employees.Healthcare identity data has long-lived value and creates exposure that persists well beyond incident containment.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Anthem_medical_data_breach2015-06-04OPM breach announcedincidentThe U.S. Office of Personnel Management disclosed a major incident affecting federal personnel and background-investigation data.The breach demonstrated the intelligence value of aggregated identity and personnel information.shield-exclamation#EA580Ctruereviewed2026-09-26https://www.opm.gov/frequently-asked-questions/cybersecurity-information-faq/cybersecurity-june-4-2015/where-can-i-find-information-on-the-recent-cybersecurity-incidents/https://en.wikipedia.org/wiki/Office_of_Personnel_Management_data_breach2015-07-08Hacking Team breachincidentHacking Team's internal data and source code were leaked following a compromise.The breach exposed the commercial offensive-security ecosystem and fueled debate over zero-day markets and surveillance technology.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Hacking_Team2015-07-20Ashley Madison breach disclosedincidentAttackers disclosed a compromise of Ashley Madison and later released stolen user data.The incident highlighted the personal, legal, and reputational consequences of breaches involving highly sensitive behavioral data.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Ashley_Madison_data_breach2015-12-23Ukraine power grid cyberattackcritical_infrastructureA coordinated cyber operation disrupted electricity distribution in Ukraine through enterprise compromise and control-system access.It became one of the defining examples of cyber operations causing real-world critical-infrastructure disruption.industry#0E7490trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/2015_Ukraine_power_grid_hack2016-02-04Bangladesh Bank cyber heistincidentAttackers used compromised systems and fraudulent SWIFT messages in an attempt to steal nearly $1 billion from Bangladesh Bank.The heist showed how cyber compromise can manipulate trusted financial messaging and payment processes.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery2016-02-16Hollywood Presbyterian ransomware paymentmalwareA hospital paid ransom after ransomware disrupted access to systems and records.Healthcare became one of the earliest sectors to show how ransomware could affect service delivery and patient-care operations.bug#DC2626trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Hollywood_Presbyterian_Medical_Center_ransomware_attack2016-06-14DNC intrusion disclosednation_stateThe Democratic National Committee disclosed a network compromise attributed by investigators to Russian intelligence-linked groups.The incident became a landmark example of cyber-enabled information operations intersecting with political processes.crosshairs#7C3AEDtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Democratic_National_Committee_cyber_attacks2016-08-13Shadow Brokers leaks beginnation_stateThe Shadow Brokers published tools and exploits allegedly associated with the Equation Group.Leakage of high-end offensive tooling can rapidly convert state-developed capabilities into broad criminal attack risk.crosshairs#7C3AEDtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/The_Shadow_Brokers2016-10-21Mirai / Dyn DDoS attackinternetA massive DDoS attack targeted DNS provider Dyn using the Mirai botnet, disrupting access to major online services.The attack made insecure IoT devices part of the global threat model and highlighted DNS as critical shared infrastructure.globe#0369A1trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/2016_Dyn_cyberattack2017-02-23CloudbleedvulnerabilityCloudflare disclosed a memory-leak bug that could expose sensitive data from customer websites.Shared cloud and edge infrastructure bugs can create cross-tenant confidentiality risk.triangle-exclamation#2563EBtruereviewed2026-09-26https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug/https://en.wikipedia.org/wiki/Cloudbleed2017-03-01NYDFS Cybersecurity RegulationgovernanceNew York's cybersecurity regulation took effect for covered financial institutions.The rule helped normalize executive accountability, risk assessment, incident reporting, and program governance in financial services.scale-balanced#B7791Ftruereviewed2026-09-26https://www.dfs.ny.gov/industry_guidance/cybersecurityhttps://en.wikipedia.org/wiki/New_York_State_Department_of_Financial_Services2017-03-14MS17-010 releasedvulnerabilityMicrosoft fixed critical SMBv1 vulnerabilities including the flaw later associated with EternalBlue.Organizations had nearly two months to patch before WannaCry weaponized the flaw at global scale.triangle-exclamation#2563EBtruereviewed2026-09-26https://learn.microsoft.com/en-us/security-updates/securitybulletins/2017/ms17-010https://en.wikipedia.org/wiki/EternalBlue2017-04-14EternalBlue exploit released publiclyvulnerabilityThe Shadow Brokers released offensive tooling including EternalBlue.Public release of weaponized exploit code dramatically shortened the path from vulnerability to widespread criminal use.triangle-exclamation#2563EBtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/EternalBlue2017-05-12WannaCrymalwareWannaCry spread globally by exploiting an SMB vulnerability Microsoft had patched two months earlier.It remains a defining example of the cost of delayed patching, unsupported systems, and flat networks.bug#DC2626truereviewed2026-09-26https://www.microsoft.com/en-us/security/blog/2017/05/12/wannacrypt-ransomware-worm-targets-out-of-date-systems/https://en.wikipedia.org/wiki/WannaCry_ransomware_attack2017-06-27NotPetyasupply_chainNotPetya spread from compromised Ukrainian software into organizations around the world and functioned primarily as destructive malware.It remains a textbook example of a targeted supply-chain compromise creating enormous unintended blast radius.link#0F766Etruereviewed2026-09-26https://www.microsoft.com/en-us/security/blog/2017/06/27/new-ransomware-old-techniques-Petya-adds-worm-capabilities/https://en.wikipedia.org/wiki/2017_Ukraine_ransomware_attacks2017-09-07Equifax breach announcedincidentEquifax disclosed a major incident involving highly sensitive consumer identity data.It became a defining case for vulnerability management, data concentration, executive accountability, and identity risk.shield-exclamation#EA580Ctruereviewed2026-09-26https://investor.equifax.com/news-events/press-releases/detail/240/equifax-announces-cybersecurity-incident-involving-consumerhttps://en.wikipedia.org/wiki/2017_Equifax_data_breach2017-10-16KRACK disclosedvulnerabilityResearchers disclosed key reinstallation attacks against WPA2.Even mature, ubiquitous security protocols can fail through subtle state-machine and implementation flaws.triangle-exclamation#2563EBtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/KRACK2017-11-21Uber breach disclosedincidentUber disclosed a 2016 breach involving personal data for millions of riders and drivers and acknowledged paying the attackers.The incident became a governance case study in breach disclosure, extortion, and executive accountability.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Uber#Data_breaches2018-01-03Meltdown and SpectrevulnerabilityResearchers disclosed speculative-execution attacks affecting modern processors.The flaws showed that security failures can exist below the operating system and require coordinated hardware and software fixes.triangle-exclamation#2563EBtruereviewed2026-09-26https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/answering-your-questions-about-meltdown-and-spectre/https://en.wikipedia.org/wiki/Spectre_(security_vulnerability)2018-02-27GitHub 1.35 Tbps DDoSinternetGitHub experienced a record-setting DDoS attack amplified through exposed memcached servers.Misconfigured Internet infrastructure can be weaponized for enormous amplification attacks.globe#0369A1truereviewed2026-09-26https://github.blog/news-insights/company-news/ddos-incident-report/https://en.wikipedia.org/wiki/Memcached2018-03-17Cambridge Analytica scandal breaks widelygovernanceReporting revealed large-scale harvesting and political use of Facebook user data through a third-party app ecosystem.The scandal accelerated scrutiny of platform data governance, consent, third-party access, and privacy accountability.scale-balanced#B7791Ftrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Facebook%E2%80%93Cambridge_Analytica_data_scandal2018-05-25GDPR becomes applicablegovernanceThe EU General Data Protection Regulation became applicable across member states.GDPR materially changed the global privacy landscape and made data governance, security, and privacy inseparable executive concerns.scale-balanced#B7791Ftruereviewed2026-09-26https://eur-lex.europa.eu/content/news/general-data-protection-regulation-GDPR-applies-from-25-May-2018.htmlhttps://en.wikipedia.org/wiki/General_Data_Protection_Regulation2018-06-28CCPA signedgovernanceCalifornia enacted the Consumer Privacy Act, creating new rights around access, deletion, disclosure, and sale of personal information.CCPA helped establish a U.S. state-level privacy model that influenced subsequent legislation.scale-balanced#B7791Ftruereviewed2026-09-26https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180AB375https://en.wikipedia.org/wiki/California_Consumer_Privacy_Act2018-07-20SingHealth breach disclosedincidentSingapore disclosed theft of personal data belonging to about 1.5 million SingHealth patients.Healthcare data has long-term intelligence and identity-abuse value, not merely immediate financial value.shield-exclamation#EA580Ctruereviewed2026-09-26https://www.moh.gov.sg/newsroom/singhealth%27s-it-system-target-of-cyberattack/https://en.wikipedia.org/wiki/2018_SingHealth_data_breach2018-11-16CISA establishedmilestoneThe Cybersecurity and Infrastructure Security Agency Act formally established CISA.CISA became the central U.S. civilian agency for cyber defense, critical-infrastructure security, and vulnerability coordination.star#15803Dtruereviewed2026-09-26https://www.cisa.gov/news-events/alerts/2018/11/19/cybersecurity-and-infrastructure-security-agencyhttps://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency2018-11-30Marriott / Starwood breach disclosedincidentMarriott announced unauthorized access to the Starwood reservation database involving a large volume of guest data.The incident highlighted acquisition due diligence, inherited technology risk, data retention, and long attacker dwell time.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Marriott_International_data_breach2019-03-19Norsk Hydro ransomware attackmalwareNorsk Hydro suffered a ransomware attack that disrupted global operations and forced substantial manual processing.Its response became a widely cited example of transparent crisis communication and resilience.bug#DC2626trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Norsk_Hydro_ransomware_attack2019-05-07Baltimore ransomware attackmalwareBaltimore city systems were disrupted by ransomware, affecting email, property transactions, billing, and municipal services.Ransomware can become a public-service continuity problem, not merely an IT outage.bug#DC2626trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/2019_Baltimore_ransomware_attack2019-05-14BlueKeepvulnerabilityMicrosoft released fixes for a pre-authentication remote-code-execution vulnerability in Remote Desktop Services and warned it was wormable.BlueKeep reinforced the danger of exposed remote administration and end-of-life systems.triangle-exclamation#2563EBtruereviewed2026-09-26https://www.microsoft.com/en-us/msrc/blog/2019/05/prevent-a-worm-by-updating-remote-desktop-services-cve-2019-0708https://en.wikipedia.org/wiki/BlueKeep2019-07-29Capital One breach announcedincidentCapital One disclosed unauthorized access to personal information associated with credit-card applications and customers.The breach became a cloud-security case study in configuration, identity, metadata services, and least privilege.shield-exclamation#EA580Ctruereviewed2026-09-26https://www.capitalone.com/about/newsroom/capital-one-announces-data-security-incident/https://en.wikipedia.org/wiki/2019_Capital_One_cyber_incident2020-01-14Windows 7 end of supportmilestoneMicrosoft ended routine support for Windows 7.End-of-life operating systems become long-term security liabilities when organizations cannot retire or isolate them.star#15803Dtruereviewed2026-09-26https://support.microsoft.com/en-us/windows/windows-7-support-ended-on-january-14-2020-b75dcd83-19f2-b6e3-2d1f-3f15a4f6f7f9https://en.wikipedia.org/wiki/Windows_72020-07-15Twitter account takeoveridentityAttackers compromised internal tools and took over numerous high-profile Twitter accounts to promote a cryptocurrency scam.Privileged support workflows can bypass strong user-facing security controls.key#4F46E5trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/2020_Twitter_account_hijacking2020-07-23Garmin ransomware outagemalwareGarmin experienced a major outage affecting online services, support, and connected-device synchronization following ransomware.Ransomware can disrupt both enterprise operations and customer-facing connected services.bug#DC2626trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Garmin#2020_outage2020-09-10Düsseldorf hospital ransomware incidentcritical_infrastructureA ransomware incident disrupted systems at a German hospital and was associated with diversion of an emergency patient.Cyber incidents in healthcare can create real-world safety consequences.industry#0E7490trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/2020_D%C3%BCsseldorf_University_Hospital_cyberattack2020-12-08FireEye breach disclosedincidentFireEye disclosed that a sophisticated actor stole proprietary Red Team assessment tools.The incident showed the value attackers place on security tooling and the need for rapid public defensive action after compromise.shield-exclamation#EA580Ctruereviewed2026-09-26https://www.mandiant.com/resources/blog/unauthorized-access-of-fireeye-red-team-toolshttps://en.wikipedia.org/wiki/FireEye2020-12-13SolarWinds Orion compromisesupply_chainCISA warned of active exploitation involving compromised SolarWinds Orion releases delivered through trusted updates.SolarWinds changed how boards and security teams think about software supply chains and privileged management platforms.link#0F766Etruereviewed2026-09-26https://www.cisa.gov/news-events/alerts/2020/12/13/active-exploitation-solarwinds-softwarehttps://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach2021-03-02HAFNIUM / Exchange zero-daysnation_stateMicrosoft disclosed active exploitation of previously unknown Exchange Server vulnerabilities by a China-based threat actor it called HAFNIUM.Internet-facing messaging infrastructure became a direct path into enterprise networks.crosshairs#7C3AEDtruereviewed2026-09-26https://blogs.microsoft.com/on-the-issues/2021/03/02/new-nation-state-cyberattacks/https://en.wikipedia.org/wiki/2021_Microsoft_Exchange_Server_data_breach2021-05-07Colonial Pipeline ransomwarecritical_infrastructureColonial Pipeline experienced a network disruption that led to shutdown of pipeline operations; the FBI later confirmed DarkSide ransomware.A business-system compromise can create physical-world consequences when operations are shut down for safety or containment.industry#0E7490truereviewed2026-09-26https://www.fbi.gov/news/press-releases/fbi-statement-on-network-disruption-at-colonial-pipelinehttps://en.wikipedia.org/wiki/Colonial_Pipeline_ransomware_attack2021-05-30JBS ransomware attackmalwareJBS experienced a ransomware attack that disrupted meat-processing operations in multiple countries.Ransomware against concentrated suppliers can create broader economic and supply-chain risk.bug#DC2626trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/JBS_S.A.#Cyberattack2021-07-01PrintNightmarevulnerabilityCritical Windows Print Spooler vulnerabilities and public exploit code drew widespread attention.Legacy services can create high-impact enterprise attack paths, and disclosure confusion can complicate remediation.triangle-exclamation#2563EBtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/PrintNightmare2021-07-02Kaseya VSA ransomware attacksupply_chainA ransomware campaign exploited Kaseya VSA and affected managed service providers and downstream customers.Management platforms offer attackers enormous leverage because one compromise can cascade into many customers.link#0F766Etruereviewed2026-09-26https://content.govdelivery.com/accounts/USDHSCISA/bulletins/2e6a462https://en.wikipedia.org/wiki/Kaseya_VSA_ransomware_attack2021-11-03CISA Known Exploited Vulnerabilities catalogmilestoneCISA issued BOD 22-01 and operationalized the Known Exploited Vulnerabilities catalog for federal remediation prioritization.It helped shift vulnerability management toward exploitation evidence and real-world risk rather than severity scores alone.star#15803Dtruereviewed2026-09-26https://www.cisa.gov/news-events/directiveshttps://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency2021-12-10Log4ShellvulnerabilityLog4Shell exposed remote-code-execution risk in widely deployed Apache Log4j versions through JNDI lookup behavior.It showed how hidden software dependencies can become enterprise-wide security emergencies.triangle-exclamation#2563EBtruereviewed2026-09-26https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-356ahttps://en.wikipedia.org/wiki/Log4Shell2022-01-13WhisperGate destructive malwarenation_stateMicrosoft described destructive malware targeting Ukrainian organizations and masquerading as ransomware.The campaign foreshadowed use of cyber operations alongside escalating geopolitical conflict.crosshairs#7C3AEDtruereviewed2026-09-26https://www.microsoft.com/en-us/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/https://en.wikipedia.org/wiki/2022_Ukraine_cyberattacks2022-02-23HermeticWiper attacksnation_stateDestructive wiper malware was deployed against Ukrainian organizations immediately before Russia's full-scale invasion.The campaign showed how destructive cyber operations can be integrated into broader military conflict.crosshairs#7C3AEDtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/2022_Ukraine_cyberattacks2022-03-22Okta / LAPSUS$ incident disclosedidentityOkta disclosed details around a third-party support engineer compromise after LAPSUS$ published screenshots suggesting access.The incident highlighted identity-provider concentration and privileged third-party support risk.key#4F46E5trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Lapsus$2022-03-31Spring4ShellvulnerabilityA critical Spring Framework vulnerability could enable unauthenticated remote code execution under affected configurations.It reinforced the challenge of rapidly understanding application-framework exposure across large software estates.triangle-exclamation#2563EBtruereviewed2026-09-26https://cert.europa.eu/publications/security-advisories/2022-023/https://en.wikipedia.org/wiki/Spring_Framework2022-04-06Costa Rica ransomware crisismalwareConti ransomware attacks disrupted multiple Costa Rican government agencies and public services.The crisis showed ransomware reaching a level where a national government declared an emergency.bug#DC2626trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/2022_Costa_Rican_ransomware_attack2022-08-25LastPass development-environment breachidentityLastPass disclosed unauthorized access to portions of its development environment through a compromised developer account.Technical information and developer access can become building blocks for follow-on compromise.key#4F46E5truereviewed2026-09-26https://blog.lastpass.com/posts/notice-of-security-incidenthttps://en.wikipedia.org/wiki/LastPass2022-09-15Uber intrusionidentityUber disclosed a security incident after an attacker gained broad internal access using social engineering and compromised credentials.The incident reinforced the importance of phishing-resistant authentication and privileged-access segmentation.key#4F46E5trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Uber#2022_security_breach2022-09-22Optus breachincidentAustralian telecom provider Optus disclosed a major breach involving customer identity information.Telecommunications providers are high-value targets because they combine identity, account, device, and communications data.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/2022_Optus_data_breach2022-10-13Medibank cyber incidentincidentAustralian health insurer Medibank disclosed an incident that later involved theft and publication of highly sensitive customer data.Health and claims data can create extreme privacy harm when stolen and used for extortion.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/2022_Medibank_cyberattack2022-11-01OpenSSL CVE-2022-3602 / 3786vulnerabilityOpenSSL released fixes for certificate-parsing vulnerabilities that drew broad attention because of the library's ubiquity.The episode reinforced the need for rapid dependency inventory when shared libraries are affected.triangle-exclamation#2563EBtruereviewed2026-09-26https://www.openssl.org/news/secadv/20221101.txthttps://en.wikipedia.org/wiki/OpenSSL2023-01-11Royal Mail ransomware incidentmalwareA ransomware incident disrupted Royal Mail's international export services.Ransomware against logistics and postal systems can interrupt physical commerce and supply chains.bug#DC2626trueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Royal_Mail#2023_cyber_incident2023-02-02ESXiArgs campaignmalwareWidespread ransomware exploitation targeted Internet-exposed VMware ESXi systems.Exposed virtualization infrastructure creates difficult recovery scenarios when hypervisors themselves are encrypted.bug#DC2626truereviewed2026-09-26https://www.cisa.gov/news-events/alerts/2023/02/09/cisa-and-fbi-release-esxiargs-ransomware-recovery-guidancehttps://en.wikipedia.org/wiki/VMware_ESXi2023-03-293CX supply-chain compromisesupply_chainA trojanized 3CX desktop application was used in a supply-chain attack affecting downstream customers.Trusted signed software can become an attack-delivery channel when development or build environments are compromised.link#0F766Etruereviewed2026-09-26https://www.cisa.gov/news-events/alerts/2023/03/30/supply-chain-attack-against-3cxdesktopapphttps://en.wikipedia.org/wiki/3CX2023-05-31MOVEit zero-day disclosedsupply_chainProgress Software released patches for a critical MOVEit Transfer vulnerability after signs of active exploitation.One widely used file-transfer product created cascading third-party data exposure across many organizations.link#0F766Etruereviewed2026-09-26https://www.sec.gov/Archives/edgar/data/876167/000087616723000113/prgs-20230530.htmhttps://en.wikipedia.org/wiki/2023_MOVEit_data_breach2023-07-26SEC cybersecurity disclosure rulesgovernanceThe SEC adopted rules requiring public companies to disclose material cyber incidents and annual information about risk management and governance.Cybersecurity materiality and governance became explicit securities-law concerns for public companies.scale-balanced#B7791Ftruereviewed2026-09-26https://www.sec.gov/newsroom/press-releases/2023-139https://en.wikipedia.org/wiki/U.S._Securities_and_Exchange_Commission2023-09-12MGM Resorts cyber incidentincidentMGM Resorts disclosed a cybersecurity issue affecting U.S. systems and significant property operations.The event showed how identity compromise and containment can rapidly become visible business-operations problems.shield-exclamation#EA580Ctruereviewed2026-09-26https://www.sec.gov/Archives/edgar/data/789570/000119312523233855/d502352dex991.htmhttps://en.wikipedia.org/wiki/MGM_Resorts_International2023-09Caesars Entertainment cyber incidentincidentCaesars disclosed a cyber incident involving theft of loyalty-program customer data and payment to attackers.The event reinforced the value of identity data and the role of social engineering in hospitality attacks.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Caesars_Entertainment2023-10-10Citrix BleedvulnerabilityCitrix released updates for a NetScaler vulnerability later associated with session-token theft and session hijacking.Patching alone may not terminate attacker access obtained before remediation; session invalidation can also be required.triangle-exclamation#2563EBtruereviewed2026-09-26https://www.cisa.gov/guidance-addressing-citrix-netscaler-adc-and-gateway-vulnerability-cve-2023-4966-citrix-bleedhttps://en.wikipedia.org/wiki/NetScaler2023-10-20Okta support-system breachidentityOkta disclosed unauthorized access to its customer support case-management system using a stolen credential.Identity providers sit at a uniquely sensitive trust boundary, including supporting systems and uploaded troubleshooting artifacts.key#4F46E5truereviewed2026-09-26https://sec.okta.com/articles/2023/10/tracking-unauthorized-access-oktas-support-system/https://en.wikipedia.org/wiki/Okta,_Inc.2023-10-30SEC charges SolarWinds and CISOgovernanceThe SEC filed civil charges against SolarWinds and its CISO alleging fraud and internal-control failures related to cybersecurity disclosures.The case intensified scrutiny of executive cybersecurity statements, disclosure controls, and personal accountability.scale-balanced#B7791Ftruereviewed2026-09-26https://www.sec.gov/newsroom/press-releases/2023-227https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach2024-01-10Ivanti Connect Secure zero-daysvulnerabilityIvanti disclosed critical vulnerabilities affecting Connect Secure and Policy Secure appliances that were being exploited.Internet-facing security appliances are prime initial-access targets and require rapid patching plus compromise assessment.triangle-exclamation#2563EBtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Ivanti2024-02-21Change Healthcare cyberattackcritical_infrastructureUnitedHealth disclosed a cyberattack affecting Change Healthcare and disrupting claims, payments, pharmacy, and healthcare transactions.Concentration in a critical third-party platform can turn one compromise into a sector-wide operational problem.industry#0E7490truereviewed2026-09-26https://www.sec.gov/Archives/edgar/data/731766/000073176624000045/unh-20240221.htmhttps://en.wikipedia.org/wiki/Change_Healthcare2024-02-26NIST Cybersecurity Framework 2.0governanceNIST released CSF 2.0, expanding applicability and adding the Govern function.It formalized cybersecurity as an enterprise governance responsibility, not merely a technical function.scale-balanced#B7791Ftruereviewed2026-09-26https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-frameworkhttps://en.wikipedia.org/wiki/NIST_Cybersecurity_Framework2024-03-29XZ Utils backdoorsupply_chainA sophisticated backdoor was discovered in XZ Utils 5.6.0 and 5.6.1 after malicious code entered upstream release tarballs.Patient compromise of an open-source project can create risk far beyond the original repository.link#0F766Etruereviewed2026-09-26https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094https://en.wikipedia.org/wiki/XZ_Utils_backdoor2024-04-12PAN-OS CVE-2024-3400 disclosedvulnerabilityPalo Alto Networks disclosed a critical command-injection vulnerability affecting GlobalProtect on certain PAN-OS configurations.Security perimeter devices can become privileged attack paths when Internet-facing components are exploitable.triangle-exclamation#2563EBtruereviewed2026-09-26https://nvd.nist.gov/vuln/detail/CVE-2024-3400https://en.wikipedia.org/wiki/Palo_Alto_Networks2024-05Snowflake customer compromises emergeincidentA campaign involving stolen customer credentials affected multiple organizations using Snowflake-hosted data environments.Shared cloud platforms amplify the importance of MFA, credential hygiene, and identity logging.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Snowflake_Inc.2024-05-31Live Nation / Ticketmaster cloud incidentincidentLive Nation disclosed unauthorized activity in a third-party cloud database environment containing company data including Ticketmaster information.The incident highlighted third-party cloud concentration and the use of stolen credentials against SaaS and data platforms.shield-exclamation#EA580Ctruereviewed2026-09-26https://www.sec.gov/Archives/edgar/data/1335258/000133525824000081/lyv-20240531.htmhttps://en.wikipedia.org/wiki/Ticketmaster2024-06-26Polyfill.io compromisesupply_chainCloudflare reported that the popular polyfill.io JavaScript service could no longer be trusted after malicious code injection.Externally hosted client-side dependencies can silently become supply-chain channels into huge numbers of websites.link#0F766Etruereviewed2026-09-26https://blog.cloudflare.com/automatically-replacing-polyfill-io-links-with-cloudflares-mirror-for-a-safer-internet/https://en.wikipedia.org/wiki/Polyfill_(programming)2024-07-01regreSSHionvulnerabilityQualys disclosed an unauthenticated remote-code-execution vulnerability in OpenSSH server on affected glibc-based Linux systems.Fixed vulnerabilities can return through code changes; regression testing matters even for mature infrastructure software.triangle-exclamation#2563EBtruereviewed2026-09-26https://www.qualys.com/regresshion-cve-2024-6387https://en.wikipedia.org/wiki/OpenSSH2024-07-19CrowdStrike Channel File 291 outageinternetA CrowdStrike content configuration update triggered Windows system crashes at global scale; CrowdStrike said it was not a cyberattack.The outage demonstrated concentration risk in security tooling and the importance of staged deployment, rollback, validation, and resilience.globe#0369A1truereviewed2026-09-26https://www.crowdstrike.com/en-us/blog/falcon-content-update-preliminary-post-incident-report/https://en.wikipedia.org/wiki/2024_CrowdStrike-related_IT_outages2024-08-01EU AI Act enters into forcegovernanceThe European Union's AI Act entered into force, establishing a risk-based legal framework for artificial intelligence systems.AI governance became a formal compliance discipline increasingly intersecting with cybersecurity, privacy, and digital trust.scale-balanced#B7791Ftruereviewed2026-09-26https://commission.europa.eu/news-and-media/news/ai-act-enters-force-2024-08-01_enhttps://en.wikipedia.org/wiki/Artificial_Intelligence_Act2024-09Salt Typhoon telecom intrusions become publicnation_stateReports described a China-linked campaign compromising major telecommunications providers and sensitive communications infrastructure.Telecom infrastructure is strategic because compromise can provide access to communications, metadata, and intelligence collection.crosshairs#7C3AEDtrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/Salt_Typhoon2024-10-17NIS2 transposition deadlinegovernanceEU member states reached the deadline for transposing the NIS2 Directive into national law.NIS2 raised expectations for governance, supply-chain security, incident reporting, and executive accountability.scale-balanced#B7791Ftrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/NIS2_Directive2024-12-10EU Cyber Resilience Act enters into forcegovernanceThe Cyber Resilience Act entered into force, establishing cybersecurity requirements for products with digital elements.It moves software and hardware security toward lifecycle duty of care, secure-by-design expectations, and manufacturer accountability.scale-balanced#B7791Ftruereviewed2026-09-26https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-acthttps://en.wikipedia.org/wiki/Cyber_Resilience_Act2025-01-07PowerSchool breach publicly reportedincidentPowerSchool disclosed unauthorized access to its student information system environment and data belonging to school districts.Concentrated education platforms hold sensitive data on students, parents, and staff and create broad downstream exposure when compromised.shield-exclamation#EA580Ctrueneeds_primary_source2026-09-26https://en.wikipedia.org/wiki/PowerSchool