Longo.org Cyber History Calendar Canonical source dataset for the Longo.org Cyber History Calendar. 2026-09-26 133 bug #DC2626 shield-exclamation #EA580C triangle-exclamation #2563EB crosshairs #7C3AED link #0F766E scale-balanced #B7791F industry #0E7490 key #4F46E5 globe #0369A1 star #15803D 1983-11-10 Fred Cohen virus demonstration milestone Fred Cohen demonstrated self-replicating code during academic security research, helping formalize the modern computer-virus concept. It helped turn malicious self-replication into a defined computer-security problem. star #15803D true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Fred_Cohen 1986-01 Brain boot-sector virus malware Brain spread through infected floppy-disk boot sectors and is widely cited as the first IBM PC-compatible virus to circulate broadly. It marks malware's transition from research curiosity to something that could spread through ordinary computer use. bug #DC2626 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Brain_(computer_virus) 1988-11-02 Morris Worm malware The Morris Worm spread rapidly across the early Internet, exploiting multiple weaknesses and affecting thousands of systems. It became a foundational Internet security incident and helped drive organized incident-response capability. bug #DC2626 true reviewed 2026-09-26 https://www.fbi.gov/history/famous-cases/morris-worm https://en.wikipedia.org/wiki/Morris_worm 1988-11-17 CERT Coordination Center established milestone DARPA funded creation of the CERT Coordination Center at Carnegie Mellon after the Morris Worm. Modern incident coordination and vulnerability-response practices trace directly to needs exposed by early Internet-wide incidents. star #15803D true reviewed 2026-09-26 https://www.sei.cmu.edu/about/divisions/cert/index.cfm https://en.wikipedia.org/wiki/CERT_Coordination_Center 1989-12 AIDS Trojan / PC Cyborg malware The AIDS Trojan was distributed on floppy disks, hid directories, encrypted filenames, and demanded payment by postal mail. Often cited as the first ransomware, it proves the extortion model predates cryptocurrency by decades. bug #DC2626 true reviewed 2026-09-26 https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/aids-trojan https://en.wikipedia.org/wiki/PC_Cyborg 1990-06 UK Computer Misuse Act governance The United Kingdom enacted the Computer Misuse Act, creating criminal offenses for unauthorized access and related computer misuse. It became a foundational cybercrime statute and still shapes debates over authorization and security research. scale-balanced #B7791F true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Computer_Misuse_Act_1990 1993-07 First DEF CON milestone The first DEF CON brought hackers, researchers, and security practitioners together in Las Vegas. DEF CON became one of the most influential forums for practical security research and hacker culture. star #15803D true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/DEF_CON 1995-02 SSL 2.0 era begins internet Netscape introduced SSL to protect web communications and support secure commercial use of the Internet. Encrypted web transport became a basic expectation for online trust, despite weaknesses in early versions. globe #0369A1 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Transport_Layer_Security 1998-08-03 Back Orifice released malware Cult of the Dead Cow released Back Orifice, a remote-administration tool that could covertly control Windows systems. It popularized the concept of remote-access trojans and abuse of legitimate administration functions. bug #DC2626 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Back_Orifice 1999-03-26 Melissa malware Melissa spread through infected Word documents and Outlook address books, disrupting enterprise mail systems. Attackers still win by abusing trust, familiar file formats, and legitimate communication channels. bug #DC2626 true reviewed 2026-09-26 https://www.fbi.gov/news/stories/melissa-virus-20th-anniversary-032519 https://en.wikipedia.org/wiki/Melissa_(computer_virus) 1999-04-26 CIH / Chernobyl virus malware CIH overwrote hard-drive data and, on some systems, flash BIOS content when it activated. It is an early example of malware designed for destructive impact beyond nuisance or propagation. bug #DC2626 true reviewed 2026-09-26 https://www.sei.cmu.edu/documents/520/1999_019_001_496442.pdf https://en.wikipedia.org/wiki/CIH_(computer_virus) 1999-09 CVE initiative launched milestone MITRE launched Common Vulnerabilities and Exposures to give publicly known vulnerabilities standardized identifiers. CVE created a shared language for vulnerability management across vendors, scanners, advisories, and defenders. star #15803D true reviewed 2026-09-26 https://www.cve.org/About/History https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures 2000-02 Major Internet DDoS attacks internet Distributed denial-of-service attacks disrupted major Internet properties including Yahoo, Amazon, CNN, and eBay. They demonstrated that even major online services could be overwhelmed through coordinated abuse of compromised systems. globe #0369A1 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/MafiaBoy 2000-05-04 ILOVEYOU / Love Letter worm malware The Love Letter worm spread through a malicious Visual Basic Script attachment and automated forwarding. It combined human psychology with automated propagation, a pattern still visible in modern phishing and malware delivery. bug #DC2626 true reviewed 2026-09-26 https://www.sei.cmu.edu/documents/507/2000_019_001_496188.pdf https://en.wikipedia.org/wiki/ILOVEYOU 2001-02-12 Anna Kournikova worm malware A social-engineering worm disguised as an image of tennis player Anna Kournikova spread widely through email. Compelling lures and trusted communication channels remain durable malware-delivery techniques. bug #DC2626 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Anna_Kournikova_(computer_virus) 2001-07-19 Code Red malware Code Red exploited a vulnerability in Microsoft IIS and infected hundreds of thousands of Internet-facing systems. Self-propagating attacks against exposed infrastructure can move faster than human remediation processes. bug #DC2626 true reviewed 2026-09-26 https://news.microsoft.com/source/2001/07/30/government-and-industry-groups-warn-code-red-internet-worm-ready-for-serious-strike-urge-preventative-measures/ https://en.wikipedia.org/wiki/Code_Red_(computer_worm) 2001-09-18 Nimda malware Nimda spread through email, network shares, compromised websites, vulnerable IIS servers, and earlier backdoors. It demonstrated the danger of combining multiple propagation vectors into one campaign. bug #DC2626 true reviewed 2026-09-26 https://seclists.org/cert/2001/22 https://en.wikipedia.org/wiki/Nimda 2002-04 Klez worm surge malware Klez became a widespread email worm, spoofing sender addresses and distributing infected attachments. Sender spoofing and trusted-channel abuse remain basic ingredients of modern social engineering. bug #DC2626 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Klez 2003-01-25 SQL Slammer malware Slammer exploited a previously patched SQL Server flaw and caused a dramatic global traffic spike. It remains a classic example of how quickly a worm can weaponize a known vulnerability when patching lags. bug #DC2626 true reviewed 2026-09-26 https://news.microsoft.com/source/2003/01/25/microsoft-statement-on-the-slammer-worm-attack/ https://en.wikipedia.org/wiki/SQL_Slammer 2003-08-11 Blaster worm malware Blaster exploited a previously patched Windows RPC vulnerability and scanned continuously for additional vulnerable hosts. It illustrates the persistent gap between patch availability and actual remediation. bug #DC2626 true reviewed 2026-09-26 https://learn.microsoft.com/en-us/troubleshoot/windows-server/security-and-malware/blaster-worm-virus-alert https://en.wikipedia.org/wiki/Blaster_(computer_worm) 2003-08-18 Sobig.F malware Sobig.F spread through email at enormous scale and generated significant mail disruption. Mass-mailing malware showed how compromised endpoints could become infrastructure for large-scale abuse. bug #DC2626 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Sobig 2004-01-26 Mydoom malware Mydoom spread through email and peer-to-peer networks, opened a backdoor, and launched denial-of-service activity. Compromised endpoints quickly became infrastructure for further attacks, a pattern still seen in botnets. bug #DC2626 true reviewed 2026-09-26 https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Win32%2FMydoom https://en.wikipedia.org/wiki/Mydoom 2004-05-01 Sasser malware Sasser exploited the Windows LSASS vulnerability and could propagate without a user opening an attachment. It reinforced the risk of rapid exploitation following vulnerability disclosure. bug #DC2626 true reviewed 2026-09-26 https://news.microsoft.com/source/2004/05/02/microsoft-joins-law-enforcement-to-track-perpetrators-of-emerging-worm-attacks-against-computer-users/ https://en.wikipedia.org/wiki/Sasser_(computer_worm) 2004-12 PCI DSS 1.0 governance Major payment-card brands created the first Payment Card Industry Data Security Standard. PCI DSS became one of the most influential industry security compliance baselines. scale-balanced #B7791F true reviewed 2026-09-26 https://www.pcisecuritystandards.org/about_us/ https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard 2005-08-14 Zotob worm malware Zotob exploited a recently disclosed Windows Plug and Play vulnerability and disrupted corporate and media networks. It showed how quickly exploit code can follow a patch and why emergency vulnerability management matters. bug #DC2626 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Zotob 2006-01 WMF vulnerability crisis vulnerability A Windows Metafile vulnerability enabled drive-by exploitation through malicious images and triggered an out-of-cycle security update. Content-parsing flaws can create code-execution paths through routine web browsing. triangle-exclamation #2563EB true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Windows_Metafile_vulnerability 2007-01-17 TJX breach disclosed incident TJX disclosed unauthorized access affecting payment-card and customer data across its retail operations. The breach became an early large-scale example of wireless security, card-data, and third-party risk failures. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/TJX_Companies 2007-04-27 Estonia cyberattacks begin nation_state Estonian government, banking, media, and other online services experienced sustained disruptive cyber activity amid political tensions. The attacks became a landmark case in national cyber defense, resilience, and geopolitical cyber disruption. crosshairs #7C3AED true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/2007_cyberattacks_on_Estonia 2008-07-08 Kaminsky DNS flaw disclosed vulnerability Dan Kaminsky disclosed a fundamental DNS cache-poisoning weakness after a coordinated multi-vendor patch effort. The episode showed the systemic risk of flaws in core Internet infrastructure and the value of coordinated disclosure. triangle-exclamation #2563EB true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Dan_Kaminsky 2008-10-23 MS08-067 emergency patch vulnerability Microsoft issued an out-of-band critical update for a remotely exploitable Windows Server service vulnerability. The flaw was later exploited by Conficker and remains a classic emergency-patching case. triangle-exclamation #2563EB true reviewed 2026-09-26 https://learn.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-067 https://en.wikipedia.org/wiki/MS08-067 2008-11-21 Conficker discovered malware Conficker exploited the Windows Server service vulnerability addressed by MS08-067 and added multiple propagation techniques. It showed how unpatched systems, weak credentials, removable media, and shares can combine into durable malware spread. bug #DC2626 true reviewed 2026-09-26 https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Win32%2FConficker https://en.wikipedia.org/wiki/Conficker 2008-12 Heartland Payment Systems breach discovered incident Heartland discovered a major payment-card breach involving malware in transaction-processing systems. The case became an important milestone in payment-security accountability and processor risk. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Heartland_Payment_Systems 2009-07-04 U.S. and South Korea DDoS attacks nation_state Government, financial, and media websites in the United States and South Korea were targeted by coordinated denial-of-service attacks. The campaign reinforced the use of botnets for politically significant disruption and the difficulty of attribution. crosshairs #7C3AED true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/2009_cyberattacks_against_South_Korea_and_the_United_States 2010-01-12 Operation Aurora disclosed nation_state Google disclosed a sophisticated targeted intrusion that stole intellectual property and affected numerous large companies. Aurora was a watershed moment in public corporate disclosure of nation-state activity. crosshairs #7C3AED true reviewed 2026-09-26 https://googleblog.blogspot.com/2010/01/new-approach-to-china.html https://en.wikipedia.org/wiki/Operation_Aurora 2010-06-17 Stuxnet first identified critical_infrastructure Security researchers identified malware later shown to target specific industrial-control environments. Its discovery marked a turning point in awareness of cyber weapons designed to manipulate physical processes. industry #0E7490 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Stuxnet 2010-09-29 ICS-CERT Stuxnet advisory critical_infrastructure ICS-CERT documented Stuxnet targeting Siemens industrial-control software and using multiple advanced propagation techniques. Stuxnet permanently changed the conversation around cyber-physical risk. industry #0E7490 true reviewed 2026-09-26 https://www.cisa.gov/uscert/ics/advisories/ICSA-10-272-01 https://en.wikipedia.org/wiki/Stuxnet 2011-03-17 RSA SecurID breach disclosed identity RSA disclosed an advanced persistent threat and warned that information related to SecurID products had been extracted. Security controls with privileged trust relationships are strategic targets in their own right. key #4F46E5 true reviewed 2026-09-26 https://www.sec.gov/Archives/edgar/data/790070/000119312511070159/d8k.htm https://en.wikipedia.org/wiki/RSA_SecurID 2011-03-23 Comodo certificate compromise identity A certificate-authority reseller account was compromised and used to issue fraudulent certificates for major online services. Web trust depends on the operational security of certificate-issuance infrastructure, not cryptography alone. key #4F46E5 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Comodo_Group#Certificate_hacking 2011-04-26 PlayStation Network breach disclosed incident Sony disclosed a major compromise of PlayStation Network and Qriocity user data after taking services offline. The incident highlighted large-scale consumer identity exposure and the operational cost of prolonged outages. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/2011_PlayStation_Network_outage 2011-08-29 DigiNotar fraudulent certificates exposed identity Fraudulent certificates issued after compromise of DigiNotar were discovered, ultimately destroying trust in the certificate authority. Compromise of one PKI trust anchor can create ecosystem-wide consequences. key #4F46E5 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/DigiNotar 2012-05-28 Flame malware revealed nation_state Researchers disclosed Flame, a sophisticated espionage platform used primarily in the Middle East. Flame illustrated the growing complexity and modularity of state-aligned cyber espionage tooling. crosshairs #7C3AED true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Flame_(malware) 2012-06-06 LinkedIn password breach incident Millions of hashed LinkedIn passwords were posted online following a breach. The incident reinforced the importance of strong password hashing, unique credentials, and resistance to credential reuse. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/2012_LinkedIn_hack 2012-08-15 Shamoon attacks Saudi Aramco critical_infrastructure Shamoon was used in a destructive attack that wiped large numbers of Saudi Aramco workstations. The attack demonstrated the business impact of destructive malware and the importance of segmentation and recovery. industry #0E7490 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Shamoon 2013-02-19 Mandiant APT1 report nation_state Mandiant published a detailed report linking a large cyber-espionage campaign to a unit of China's People's Liberation Army. The report helped normalize evidence-based public attribution of state-sponsored cyber operations. crosshairs #7C3AED true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/PLA_Unit_61398 2013-03-20 DarkSeoul attacks nation_state Cyberattacks disrupted major South Korean banks and broadcasters, wiping systems and affecting operations. The incident showed how destructive malware can be used for national-level disruption. crosshairs #7C3AED true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/2013_South_Korea_cyberattack 2013-10-03 Adobe breach disclosed incident Adobe disclosed an intrusion involving customer information and source code. The breach illustrated the value attackers place on both identity data and proprietary software source code. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Adobe_Inc.#Security_breach 2013-12-19 Target breach announced incident Target confirmed unauthorized access to payment-card data affecting tens of millions of accounts. The breach became a landmark example of third-party access risk, point-of-sale compromise, and executive accountability. shield-exclamation #EA580C true reviewed 2026-09-26 https://corporate.target.com/press/release/2013/12/target-confirms-unauthorized-access-to-payment-card-data-in-u-s-stores https://en.wikipedia.org/wiki/2013_Target_data_breach 2014-02-12 NIST Cybersecurity Framework 1.0 governance NIST released the first Framework for Improving Critical Infrastructure Cybersecurity. The Framework created a common risk-based language for cybersecurity outcomes and executive communication. scale-balanced #B7791F true reviewed 2026-09-26 https://www.nist.gov/news-events/news/2014/02/nist-releases-cybersecurity-framework-version-10 https://en.wikipedia.org/wiki/NIST_Cybersecurity_Framework 2014-04-07 Heartbleed vulnerability Heartbleed exposed a flaw in OpenSSL heartbeat handling that allowed remote attackers to read portions of process memory. It showed how one defect in a ubiquitous security library can create global risk and require key rotation beyond patching. triangle-exclamation #2563EB true reviewed 2026-09-26 https://nvd.nist.gov/vuln/detail/CVE-2014-0160 https://en.wikipedia.org/wiki/Heartbleed 2014-09-08 Home Depot breach disclosed incident Home Depot disclosed a payment-card breach involving malware on point-of-sale systems. Retail breaches reinforced the need for segmentation, payment-environment hardening, and third-party access controls. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Home_Depot#Data_breach 2014-09-24 Shellshock vulnerability Shellshock allowed arbitrary command execution through crafted environment variables processed by GNU Bash. It demonstrated the systemic risk created when foundational components are embedded across enormous software estates. triangle-exclamation #2563EB true reviewed 2026-09-26 https://nvd.nist.gov/vuln/detail/CVE-2014-6271 https://en.wikipedia.org/wiki/Shellshock_(software_bug) 2014-10-02 JPMorgan Chase breach disclosed incident JPMorgan Chase disclosed a major intrusion affecting contact information associated with tens of millions of households and small businesses. The incident underscored the scale and attractiveness of identity data held by financial institutions. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/2014_JPMorgan_Chase_data_breach 2014-10-14 POODLE disclosed vulnerability Researchers disclosed a weakness in SSL 3.0 that could allow recovery of plaintext from encrypted connections. Legacy compatibility can preserve attack paths long after stronger replacements exist. triangle-exclamation #2563EB true reviewed 2026-09-26 https://security.googleblog.com/2014/10/this-poodle-bites-exploiting-ssl-30.html https://en.wikipedia.org/wiki/POODLE 2014-11-24 Sony Pictures destructive attack incident Sony Pictures suffered a destructive intrusion involving malware, stolen data, and major operational disruption. The attack showed how theft, coercion, public disclosure, and destruction can be combined in one campaign. shield-exclamation #EA580C true reviewed 2026-09-26 https://www.fbi.gov/news/press-releases/update-on-sony-investigation https://en.wikipedia.org/wiki/Sony_Pictures_hack 2015-02-04 Anthem breach disclosed incident Anthem disclosed unauthorized access to a database containing information on current and former members and employees. Healthcare identity data has long-lived value and creates exposure that persists well beyond incident containment. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Anthem_medical_data_breach 2015-06-04 OPM breach announced incident The U.S. Office of Personnel Management disclosed a major incident affecting federal personnel and background-investigation data. The breach demonstrated the intelligence value of aggregated identity and personnel information. shield-exclamation #EA580C true reviewed 2026-09-26 https://www.opm.gov/frequently-asked-questions/cybersecurity-information-faq/cybersecurity-june-4-2015/where-can-i-find-information-on-the-recent-cybersecurity-incidents/ https://en.wikipedia.org/wiki/Office_of_Personnel_Management_data_breach 2015-07-08 Hacking Team breach incident Hacking Team's internal data and source code were leaked following a compromise. The breach exposed the commercial offensive-security ecosystem and fueled debate over zero-day markets and surveillance technology. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Hacking_Team 2015-07-20 Ashley Madison breach disclosed incident Attackers disclosed a compromise of Ashley Madison and later released stolen user data. The incident highlighted the personal, legal, and reputational consequences of breaches involving highly sensitive behavioral data. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Ashley_Madison_data_breach 2015-12-23 Ukraine power grid cyberattack critical_infrastructure A coordinated cyber operation disrupted electricity distribution in Ukraine through enterprise compromise and control-system access. It became one of the defining examples of cyber operations causing real-world critical-infrastructure disruption. industry #0E7490 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/2015_Ukraine_power_grid_hack 2016-02-04 Bangladesh Bank cyber heist incident Attackers used compromised systems and fraudulent SWIFT messages in an attempt to steal nearly $1 billion from Bangladesh Bank. The heist showed how cyber compromise can manipulate trusted financial messaging and payment processes. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery 2016-02-16 Hollywood Presbyterian ransomware payment malware A hospital paid ransom after ransomware disrupted access to systems and records. Healthcare became one of the earliest sectors to show how ransomware could affect service delivery and patient-care operations. bug #DC2626 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Hollywood_Presbyterian_Medical_Center_ransomware_attack 2016-06-14 DNC intrusion disclosed nation_state The Democratic National Committee disclosed a network compromise attributed by investigators to Russian intelligence-linked groups. The incident became a landmark example of cyber-enabled information operations intersecting with political processes. crosshairs #7C3AED true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Democratic_National_Committee_cyber_attacks 2016-08-13 Shadow Brokers leaks begin nation_state The Shadow Brokers published tools and exploits allegedly associated with the Equation Group. Leakage of high-end offensive tooling can rapidly convert state-developed capabilities into broad criminal attack risk. crosshairs #7C3AED true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/The_Shadow_Brokers 2016-10-21 Mirai / Dyn DDoS attack internet A massive DDoS attack targeted DNS provider Dyn using the Mirai botnet, disrupting access to major online services. The attack made insecure IoT devices part of the global threat model and highlighted DNS as critical shared infrastructure. globe #0369A1 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/2016_Dyn_cyberattack 2017-02-23 Cloudbleed vulnerability Cloudflare disclosed a memory-leak bug that could expose sensitive data from customer websites. Shared cloud and edge infrastructure bugs can create cross-tenant confidentiality risk. triangle-exclamation #2563EB true reviewed 2026-09-26 https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug/ https://en.wikipedia.org/wiki/Cloudbleed 2017-03-01 NYDFS Cybersecurity Regulation governance New York's cybersecurity regulation took effect for covered financial institutions. The rule helped normalize executive accountability, risk assessment, incident reporting, and program governance in financial services. scale-balanced #B7791F true reviewed 2026-09-26 https://www.dfs.ny.gov/industry_guidance/cybersecurity https://en.wikipedia.org/wiki/New_York_State_Department_of_Financial_Services 2017-03-14 MS17-010 released vulnerability Microsoft fixed critical SMBv1 vulnerabilities including the flaw later associated with EternalBlue. Organizations had nearly two months to patch before WannaCry weaponized the flaw at global scale. triangle-exclamation #2563EB true reviewed 2026-09-26 https://learn.microsoft.com/en-us/security-updates/securitybulletins/2017/ms17-010 https://en.wikipedia.org/wiki/EternalBlue 2017-04-14 EternalBlue exploit released publicly vulnerability The Shadow Brokers released offensive tooling including EternalBlue. Public release of weaponized exploit code dramatically shortened the path from vulnerability to widespread criminal use. triangle-exclamation #2563EB true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/EternalBlue 2017-05-12 WannaCry malware WannaCry spread globally by exploiting an SMB vulnerability Microsoft had patched two months earlier. It remains a defining example of the cost of delayed patching, unsupported systems, and flat networks. bug #DC2626 true reviewed 2026-09-26 https://www.microsoft.com/en-us/security/blog/2017/05/12/wannacrypt-ransomware-worm-targets-out-of-date-systems/ https://en.wikipedia.org/wiki/WannaCry_ransomware_attack 2017-06-27 NotPetya supply_chain NotPetya spread from compromised Ukrainian software into organizations around the world and functioned primarily as destructive malware. It remains a textbook example of a targeted supply-chain compromise creating enormous unintended blast radius. link #0F766E true reviewed 2026-09-26 https://www.microsoft.com/en-us/security/blog/2017/06/27/new-ransomware-old-techniques-Petya-adds-worm-capabilities/ https://en.wikipedia.org/wiki/2017_Ukraine_ransomware_attacks 2017-09-07 Equifax breach announced incident Equifax disclosed a major incident involving highly sensitive consumer identity data. It became a defining case for vulnerability management, data concentration, executive accountability, and identity risk. shield-exclamation #EA580C true reviewed 2026-09-26 https://investor.equifax.com/news-events/press-releases/detail/240/equifax-announces-cybersecurity-incident-involving-consumer https://en.wikipedia.org/wiki/2017_Equifax_data_breach 2017-10-16 KRACK disclosed vulnerability Researchers disclosed key reinstallation attacks against WPA2. Even mature, ubiquitous security protocols can fail through subtle state-machine and implementation flaws. triangle-exclamation #2563EB true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/KRACK 2017-11-21 Uber breach disclosed incident Uber disclosed a 2016 breach involving personal data for millions of riders and drivers and acknowledged paying the attackers. The incident became a governance case study in breach disclosure, extortion, and executive accountability. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Uber#Data_breaches 2018-01-03 Meltdown and Spectre vulnerability Researchers disclosed speculative-execution attacks affecting modern processors. The flaws showed that security failures can exist below the operating system and require coordinated hardware and software fixes. triangle-exclamation #2563EB true reviewed 2026-09-26 https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/answering-your-questions-about-meltdown-and-spectre/ https://en.wikipedia.org/wiki/Spectre_(security_vulnerability) 2018-02-27 GitHub 1.35 Tbps DDoS internet GitHub experienced a record-setting DDoS attack amplified through exposed memcached servers. Misconfigured Internet infrastructure can be weaponized for enormous amplification attacks. globe #0369A1 true reviewed 2026-09-26 https://github.blog/news-insights/company-news/ddos-incident-report/ https://en.wikipedia.org/wiki/Memcached 2018-03-17 Cambridge Analytica scandal breaks widely governance Reporting revealed large-scale harvesting and political use of Facebook user data through a third-party app ecosystem. The scandal accelerated scrutiny of platform data governance, consent, third-party access, and privacy accountability. scale-balanced #B7791F true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Facebook%E2%80%93Cambridge_Analytica_data_scandal 2018-05-25 GDPR becomes applicable governance The EU General Data Protection Regulation became applicable across member states. GDPR materially changed the global privacy landscape and made data governance, security, and privacy inseparable executive concerns. scale-balanced #B7791F true reviewed 2026-09-26 https://eur-lex.europa.eu/content/news/general-data-protection-regulation-GDPR-applies-from-25-May-2018.html https://en.wikipedia.org/wiki/General_Data_Protection_Regulation 2018-06-28 CCPA signed governance California enacted the Consumer Privacy Act, creating new rights around access, deletion, disclosure, and sale of personal information. CCPA helped establish a U.S. state-level privacy model that influenced subsequent legislation. scale-balanced #B7791F true reviewed 2026-09-26 https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180AB375 https://en.wikipedia.org/wiki/California_Consumer_Privacy_Act 2018-07-20 SingHealth breach disclosed incident Singapore disclosed theft of personal data belonging to about 1.5 million SingHealth patients. Healthcare data has long-term intelligence and identity-abuse value, not merely immediate financial value. shield-exclamation #EA580C true reviewed 2026-09-26 https://www.moh.gov.sg/newsroom/singhealth%27s-it-system-target-of-cyberattack/ https://en.wikipedia.org/wiki/2018_SingHealth_data_breach 2018-11-16 CISA established milestone The Cybersecurity and Infrastructure Security Agency Act formally established CISA. CISA became the central U.S. civilian agency for cyber defense, critical-infrastructure security, and vulnerability coordination. star #15803D true reviewed 2026-09-26 https://www.cisa.gov/news-events/alerts/2018/11/19/cybersecurity-and-infrastructure-security-agency https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency 2018-11-30 Marriott / Starwood breach disclosed incident Marriott announced unauthorized access to the Starwood reservation database involving a large volume of guest data. The incident highlighted acquisition due diligence, inherited technology risk, data retention, and long attacker dwell time. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Marriott_International_data_breach 2019-03-19 Norsk Hydro ransomware attack malware Norsk Hydro suffered a ransomware attack that disrupted global operations and forced substantial manual processing. Its response became a widely cited example of transparent crisis communication and resilience. bug #DC2626 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Norsk_Hydro_ransomware_attack 2019-05-07 Baltimore ransomware attack malware Baltimore city systems were disrupted by ransomware, affecting email, property transactions, billing, and municipal services. Ransomware can become a public-service continuity problem, not merely an IT outage. bug #DC2626 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/2019_Baltimore_ransomware_attack 2019-05-14 BlueKeep vulnerability Microsoft released fixes for a pre-authentication remote-code-execution vulnerability in Remote Desktop Services and warned it was wormable. BlueKeep reinforced the danger of exposed remote administration and end-of-life systems. triangle-exclamation #2563EB true reviewed 2026-09-26 https://www.microsoft.com/en-us/msrc/blog/2019/05/prevent-a-worm-by-updating-remote-desktop-services-cve-2019-0708 https://en.wikipedia.org/wiki/BlueKeep 2019-07-29 Capital One breach announced incident Capital One disclosed unauthorized access to personal information associated with credit-card applications and customers. The breach became a cloud-security case study in configuration, identity, metadata services, and least privilege. shield-exclamation #EA580C true reviewed 2026-09-26 https://www.capitalone.com/about/newsroom/capital-one-announces-data-security-incident/ https://en.wikipedia.org/wiki/2019_Capital_One_cyber_incident 2020-01-14 Windows 7 end of support milestone Microsoft ended routine support for Windows 7. End-of-life operating systems become long-term security liabilities when organizations cannot retire or isolate them. star #15803D true reviewed 2026-09-26 https://support.microsoft.com/en-us/windows/windows-7-support-ended-on-january-14-2020-b75dcd83-19f2-b6e3-2d1f-3f15a4f6f7f9 https://en.wikipedia.org/wiki/Windows_7 2020-07-15 Twitter account takeover identity Attackers compromised internal tools and took over numerous high-profile Twitter accounts to promote a cryptocurrency scam. Privileged support workflows can bypass strong user-facing security controls. key #4F46E5 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/2020_Twitter_account_hijacking 2020-07-23 Garmin ransomware outage malware Garmin experienced a major outage affecting online services, support, and connected-device synchronization following ransomware. Ransomware can disrupt both enterprise operations and customer-facing connected services. bug #DC2626 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Garmin#2020_outage 2020-09-10 Düsseldorf hospital ransomware incident critical_infrastructure A ransomware incident disrupted systems at a German hospital and was associated with diversion of an emergency patient. Cyber incidents in healthcare can create real-world safety consequences. industry #0E7490 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/2020_D%C3%BCsseldorf_University_Hospital_cyberattack 2020-12-08 FireEye breach disclosed incident FireEye disclosed that a sophisticated actor stole proprietary Red Team assessment tools. The incident showed the value attackers place on security tooling and the need for rapid public defensive action after compromise. shield-exclamation #EA580C true reviewed 2026-09-26 https://www.mandiant.com/resources/blog/unauthorized-access-of-fireeye-red-team-tools https://en.wikipedia.org/wiki/FireEye 2020-12-13 SolarWinds Orion compromise supply_chain CISA warned of active exploitation involving compromised SolarWinds Orion releases delivered through trusted updates. SolarWinds changed how boards and security teams think about software supply chains and privileged management platforms. link #0F766E true reviewed 2026-09-26 https://www.cisa.gov/news-events/alerts/2020/12/13/active-exploitation-solarwinds-software https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach 2021-03-02 HAFNIUM / Exchange zero-days nation_state Microsoft disclosed active exploitation of previously unknown Exchange Server vulnerabilities by a China-based threat actor it called HAFNIUM. Internet-facing messaging infrastructure became a direct path into enterprise networks. crosshairs #7C3AED true reviewed 2026-09-26 https://blogs.microsoft.com/on-the-issues/2021/03/02/new-nation-state-cyberattacks/ https://en.wikipedia.org/wiki/2021_Microsoft_Exchange_Server_data_breach 2021-05-07 Colonial Pipeline ransomware critical_infrastructure Colonial Pipeline experienced a network disruption that led to shutdown of pipeline operations; the FBI later confirmed DarkSide ransomware. A business-system compromise can create physical-world consequences when operations are shut down for safety or containment. industry #0E7490 true reviewed 2026-09-26 https://www.fbi.gov/news/press-releases/fbi-statement-on-network-disruption-at-colonial-pipeline https://en.wikipedia.org/wiki/Colonial_Pipeline_ransomware_attack 2021-05-30 JBS ransomware attack malware JBS experienced a ransomware attack that disrupted meat-processing operations in multiple countries. Ransomware against concentrated suppliers can create broader economic and supply-chain risk. bug #DC2626 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/JBS_S.A.#Cyberattack 2021-07-01 PrintNightmare vulnerability Critical Windows Print Spooler vulnerabilities and public exploit code drew widespread attention. Legacy services can create high-impact enterprise attack paths, and disclosure confusion can complicate remediation. triangle-exclamation #2563EB true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/PrintNightmare 2021-07-02 Kaseya VSA ransomware attack supply_chain A ransomware campaign exploited Kaseya VSA and affected managed service providers and downstream customers. Management platforms offer attackers enormous leverage because one compromise can cascade into many customers. link #0F766E true reviewed 2026-09-26 https://content.govdelivery.com/accounts/USDHSCISA/bulletins/2e6a462 https://en.wikipedia.org/wiki/Kaseya_VSA_ransomware_attack 2021-11-03 CISA Known Exploited Vulnerabilities catalog milestone CISA issued BOD 22-01 and operationalized the Known Exploited Vulnerabilities catalog for federal remediation prioritization. It helped shift vulnerability management toward exploitation evidence and real-world risk rather than severity scores alone. star #15803D true reviewed 2026-09-26 https://www.cisa.gov/news-events/directives https://en.wikipedia.org/wiki/Cybersecurity_and_Infrastructure_Security_Agency 2021-12-10 Log4Shell vulnerability Log4Shell exposed remote-code-execution risk in widely deployed Apache Log4j versions through JNDI lookup behavior. It showed how hidden software dependencies can become enterprise-wide security emergencies. triangle-exclamation #2563EB true reviewed 2026-09-26 https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-356a https://en.wikipedia.org/wiki/Log4Shell 2022-01-13 WhisperGate destructive malware nation_state Microsoft described destructive malware targeting Ukrainian organizations and masquerading as ransomware. The campaign foreshadowed use of cyber operations alongside escalating geopolitical conflict. crosshairs #7C3AED true reviewed 2026-09-26 https://www.microsoft.com/en-us/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ https://en.wikipedia.org/wiki/2022_Ukraine_cyberattacks 2022-02-23 HermeticWiper attacks nation_state Destructive wiper malware was deployed against Ukrainian organizations immediately before Russia's full-scale invasion. The campaign showed how destructive cyber operations can be integrated into broader military conflict. crosshairs #7C3AED true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/2022_Ukraine_cyberattacks 2022-03-22 Okta / LAPSUS$ incident disclosed identity Okta disclosed details around a third-party support engineer compromise after LAPSUS$ published screenshots suggesting access. The incident highlighted identity-provider concentration and privileged third-party support risk. key #4F46E5 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Lapsus$ 2022-03-31 Spring4Shell vulnerability A critical Spring Framework vulnerability could enable unauthenticated remote code execution under affected configurations. It reinforced the challenge of rapidly understanding application-framework exposure across large software estates. triangle-exclamation #2563EB true reviewed 2026-09-26 https://cert.europa.eu/publications/security-advisories/2022-023/ https://en.wikipedia.org/wiki/Spring_Framework 2022-04-06 Costa Rica ransomware crisis malware Conti ransomware attacks disrupted multiple Costa Rican government agencies and public services. The crisis showed ransomware reaching a level where a national government declared an emergency. bug #DC2626 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/2022_Costa_Rican_ransomware_attack 2022-08-25 LastPass development-environment breach identity LastPass disclosed unauthorized access to portions of its development environment through a compromised developer account. Technical information and developer access can become building blocks for follow-on compromise. key #4F46E5 true reviewed 2026-09-26 https://blog.lastpass.com/posts/notice-of-security-incident https://en.wikipedia.org/wiki/LastPass 2022-09-15 Uber intrusion identity Uber disclosed a security incident after an attacker gained broad internal access using social engineering and compromised credentials. The incident reinforced the importance of phishing-resistant authentication and privileged-access segmentation. key #4F46E5 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Uber#2022_security_breach 2022-09-22 Optus breach incident Australian telecom provider Optus disclosed a major breach involving customer identity information. Telecommunications providers are high-value targets because they combine identity, account, device, and communications data. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/2022_Optus_data_breach 2022-10-13 Medibank cyber incident incident Australian health insurer Medibank disclosed an incident that later involved theft and publication of highly sensitive customer data. Health and claims data can create extreme privacy harm when stolen and used for extortion. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/2022_Medibank_cyberattack 2022-11-01 OpenSSL CVE-2022-3602 / 3786 vulnerability OpenSSL released fixes for certificate-parsing vulnerabilities that drew broad attention because of the library's ubiquity. The episode reinforced the need for rapid dependency inventory when shared libraries are affected. triangle-exclamation #2563EB true reviewed 2026-09-26 https://www.openssl.org/news/secadv/20221101.txt https://en.wikipedia.org/wiki/OpenSSL 2023-01-11 Royal Mail ransomware incident malware A ransomware incident disrupted Royal Mail's international export services. Ransomware against logistics and postal systems can interrupt physical commerce and supply chains. bug #DC2626 true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Royal_Mail#2023_cyber_incident 2023-02-02 ESXiArgs campaign malware Widespread ransomware exploitation targeted Internet-exposed VMware ESXi systems. Exposed virtualization infrastructure creates difficult recovery scenarios when hypervisors themselves are encrypted. bug #DC2626 true reviewed 2026-09-26 https://www.cisa.gov/news-events/alerts/2023/02/09/cisa-and-fbi-release-esxiargs-ransomware-recovery-guidance https://en.wikipedia.org/wiki/VMware_ESXi 2023-03-29 3CX supply-chain compromise supply_chain A trojanized 3CX desktop application was used in a supply-chain attack affecting downstream customers. Trusted signed software can become an attack-delivery channel when development or build environments are compromised. link #0F766E true reviewed 2026-09-26 https://www.cisa.gov/news-events/alerts/2023/03/30/supply-chain-attack-against-3cxdesktopapp https://en.wikipedia.org/wiki/3CX 2023-05-31 MOVEit zero-day disclosed supply_chain Progress Software released patches for a critical MOVEit Transfer vulnerability after signs of active exploitation. One widely used file-transfer product created cascading third-party data exposure across many organizations. link #0F766E true reviewed 2026-09-26 https://www.sec.gov/Archives/edgar/data/876167/000087616723000113/prgs-20230530.htm https://en.wikipedia.org/wiki/2023_MOVEit_data_breach 2023-07-26 SEC cybersecurity disclosure rules governance The SEC adopted rules requiring public companies to disclose material cyber incidents and annual information about risk management and governance. Cybersecurity materiality and governance became explicit securities-law concerns for public companies. scale-balanced #B7791F true reviewed 2026-09-26 https://www.sec.gov/newsroom/press-releases/2023-139 https://en.wikipedia.org/wiki/U.S._Securities_and_Exchange_Commission 2023-09-12 MGM Resorts cyber incident incident MGM Resorts disclosed a cybersecurity issue affecting U.S. systems and significant property operations. The event showed how identity compromise and containment can rapidly become visible business-operations problems. shield-exclamation #EA580C true reviewed 2026-09-26 https://www.sec.gov/Archives/edgar/data/789570/000119312523233855/d502352dex991.htm https://en.wikipedia.org/wiki/MGM_Resorts_International 2023-09 Caesars Entertainment cyber incident incident Caesars disclosed a cyber incident involving theft of loyalty-program customer data and payment to attackers. The event reinforced the value of identity data and the role of social engineering in hospitality attacks. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Caesars_Entertainment 2023-10-10 Citrix Bleed vulnerability Citrix released updates for a NetScaler vulnerability later associated with session-token theft and session hijacking. Patching alone may not terminate attacker access obtained before remediation; session invalidation can also be required. triangle-exclamation #2563EB true reviewed 2026-09-26 https://www.cisa.gov/guidance-addressing-citrix-netscaler-adc-and-gateway-vulnerability-cve-2023-4966-citrix-bleed https://en.wikipedia.org/wiki/NetScaler 2023-10-20 Okta support-system breach identity Okta disclosed unauthorized access to its customer support case-management system using a stolen credential. Identity providers sit at a uniquely sensitive trust boundary, including supporting systems and uploaded troubleshooting artifacts. key #4F46E5 true reviewed 2026-09-26 https://sec.okta.com/articles/2023/10/tracking-unauthorized-access-oktas-support-system/ https://en.wikipedia.org/wiki/Okta,_Inc. 2023-10-30 SEC charges SolarWinds and CISO governance The SEC filed civil charges against SolarWinds and its CISO alleging fraud and internal-control failures related to cybersecurity disclosures. The case intensified scrutiny of executive cybersecurity statements, disclosure controls, and personal accountability. scale-balanced #B7791F true reviewed 2026-09-26 https://www.sec.gov/newsroom/press-releases/2023-227 https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach 2024-01-10 Ivanti Connect Secure zero-days vulnerability Ivanti disclosed critical vulnerabilities affecting Connect Secure and Policy Secure appliances that were being exploited. Internet-facing security appliances are prime initial-access targets and require rapid patching plus compromise assessment. triangle-exclamation #2563EB true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Ivanti 2024-02-21 Change Healthcare cyberattack critical_infrastructure UnitedHealth disclosed a cyberattack affecting Change Healthcare and disrupting claims, payments, pharmacy, and healthcare transactions. Concentration in a critical third-party platform can turn one compromise into a sector-wide operational problem. industry #0E7490 true reviewed 2026-09-26 https://www.sec.gov/Archives/edgar/data/731766/000073176624000045/unh-20240221.htm https://en.wikipedia.org/wiki/Change_Healthcare 2024-02-26 NIST Cybersecurity Framework 2.0 governance NIST released CSF 2.0, expanding applicability and adding the Govern function. It formalized cybersecurity as an enterprise governance responsibility, not merely a technical function. scale-balanced #B7791F true reviewed 2026-09-26 https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework https://en.wikipedia.org/wiki/NIST_Cybersecurity_Framework 2024-03-29 XZ Utils backdoor supply_chain A sophisticated backdoor was discovered in XZ Utils 5.6.0 and 5.6.1 after malicious code entered upstream release tarballs. Patient compromise of an open-source project can create risk far beyond the original repository. link #0F766E true reviewed 2026-09-26 https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094 https://en.wikipedia.org/wiki/XZ_Utils_backdoor 2024-04-12 PAN-OS CVE-2024-3400 disclosed vulnerability Palo Alto Networks disclosed a critical command-injection vulnerability affecting GlobalProtect on certain PAN-OS configurations. Security perimeter devices can become privileged attack paths when Internet-facing components are exploitable. triangle-exclamation #2563EB true reviewed 2026-09-26 https://nvd.nist.gov/vuln/detail/CVE-2024-3400 https://en.wikipedia.org/wiki/Palo_Alto_Networks 2024-05 Snowflake customer compromises emerge incident A campaign involving stolen customer credentials affected multiple organizations using Snowflake-hosted data environments. Shared cloud platforms amplify the importance of MFA, credential hygiene, and identity logging. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Snowflake_Inc. 2024-05-31 Live Nation / Ticketmaster cloud incident incident Live Nation disclosed unauthorized activity in a third-party cloud database environment containing company data including Ticketmaster information. The incident highlighted third-party cloud concentration and the use of stolen credentials against SaaS and data platforms. shield-exclamation #EA580C true reviewed 2026-09-26 https://www.sec.gov/Archives/edgar/data/1335258/000133525824000081/lyv-20240531.htm https://en.wikipedia.org/wiki/Ticketmaster 2024-06-26 Polyfill.io compromise supply_chain Cloudflare reported that the popular polyfill.io JavaScript service could no longer be trusted after malicious code injection. Externally hosted client-side dependencies can silently become supply-chain channels into huge numbers of websites. link #0F766E true reviewed 2026-09-26 https://blog.cloudflare.com/automatically-replacing-polyfill-io-links-with-cloudflares-mirror-for-a-safer-internet/ https://en.wikipedia.org/wiki/Polyfill_(programming) 2024-07-01 regreSSHion vulnerability Qualys disclosed an unauthenticated remote-code-execution vulnerability in OpenSSH server on affected glibc-based Linux systems. Fixed vulnerabilities can return through code changes; regression testing matters even for mature infrastructure software. triangle-exclamation #2563EB true reviewed 2026-09-26 https://www.qualys.com/regresshion-cve-2024-6387 https://en.wikipedia.org/wiki/OpenSSH 2024-07-19 CrowdStrike Channel File 291 outage internet A CrowdStrike content configuration update triggered Windows system crashes at global scale; CrowdStrike said it was not a cyberattack. The outage demonstrated concentration risk in security tooling and the importance of staged deployment, rollback, validation, and resilience. globe #0369A1 true reviewed 2026-09-26 https://www.crowdstrike.com/en-us/blog/falcon-content-update-preliminary-post-incident-report/ https://en.wikipedia.org/wiki/2024_CrowdStrike-related_IT_outages 2024-08-01 EU AI Act enters into force governance The European Union's AI Act entered into force, establishing a risk-based legal framework for artificial intelligence systems. AI governance became a formal compliance discipline increasingly intersecting with cybersecurity, privacy, and digital trust. scale-balanced #B7791F true reviewed 2026-09-26 https://commission.europa.eu/news-and-media/news/ai-act-enters-force-2024-08-01_en https://en.wikipedia.org/wiki/Artificial_Intelligence_Act 2024-09 Salt Typhoon telecom intrusions become public nation_state Reports described a China-linked campaign compromising major telecommunications providers and sensitive communications infrastructure. Telecom infrastructure is strategic because compromise can provide access to communications, metadata, and intelligence collection. crosshairs #7C3AED true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/Salt_Typhoon 2024-10-17 NIS2 transposition deadline governance EU member states reached the deadline for transposing the NIS2 Directive into national law. NIS2 raised expectations for governance, supply-chain security, incident reporting, and executive accountability. scale-balanced #B7791F true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/NIS2_Directive 2024-12-10 EU Cyber Resilience Act enters into force governance The Cyber Resilience Act entered into force, establishing cybersecurity requirements for products with digital elements. It moves software and hardware security toward lifecycle duty of care, secure-by-design expectations, and manufacturer accountability. scale-balanced #B7791F true reviewed 2026-09-26 https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act https://en.wikipedia.org/wiki/Cyber_Resilience_Act 2025-01-07 PowerSchool breach publicly reported incident PowerSchool disclosed unauthorized access to its student information system environment and data belonging to school districts. Concentrated education platforms hold sensitive data on students, parents, and staff and create broad downstream exposure when compromised. shield-exclamation #EA580C true needs_primary_source 2026-09-26 https://en.wikipedia.org/wiki/PowerSchool