The 1988 internet worm exposed a missing security focal point
A GAO review of the Morris worm found no one owned Internet-wide security, and a 1991 appeals ruling tested a new computer-crime law.
Retrospective record / 100 briefs
A calm record of the incidents, advisories, standards and rulings that shaped defensive practice, with the original documents attached.
Historical event dates and source dates are separate from the preparation date of this local edition. Every brief is a retrospective draft prepared 16 September 2026; none was published on its historical date.
100 briefs
A GAO review of the Morris worm found no one owned Internet-wide security, and a 1991 appeals ruling tested a new computer-crime law.
CAIDA's measurement of the Sapphire/Slammer worm showed how a patch released six months earlier still left networks exposed.
A worm that kept spreading years after Microsoft's fix pushed security vendors, registries and ICANN into an unprecedented joint response.
Symantec's technical dossier, corroborated by two CISA advisories, described malware that hid its changes to programmable controllers from operators.
A Senate committee's kill-chain analysis found Target missed its own intrusion-detection alerts at several stages of the 2013 breach.
OpenSSL's April 2014 advisory disclosed a memory-read flaw that had been live in the library for over two years before anyone found it.
A House Oversight investigation called the breach preventable and found the agency had ignored years of inspector-general warnings.
A joint SANS and E-ISAC analysis found operators restored power within hours, and it deliberately declined to assign attribution.
A CISA alert and an academic measurement study traced Mirai's spread to just 62 factory-default username and password combinations.
The National Audit Office found unpatched systems and unclear response roles let the ransomware disrupt care at 81 NHS trusts.
Governments record how a Ukrainian accounting update carried a destructive wiper across the globe.
A federal audit and an FTC settlement trace the 2017 breach to a missed patch notice and an expired certificate.
A CISA alert and a Treasury sanctions notice together record the malware's mechanics and the US attribution to North Korea.
Vendor and coordination-center advisories show why the first Shellshock patch needed four follow-up fixes.
Researcher and vendor disclosures explain why fixing a hardware design flaw meant trading away performance.
NIST's 2017 authentication guideline asked for breach screening instead of periodic changes, and practice lagged for years.
The regulation's text and UK regulatory guidance show how a legal breach-notification deadline actually works.
MITRE's own site and design paper explain what ATT&CK is built from and what mapped coverage does not prove.
Microsoft's own bulletin and blog posts show the fix, the leak, and the warning all preceded the WannaCry worm.
An SEC settlement records how a known breach stayed off Yahoo's disclosures until a corporate sale was closing.
The company's own updates from March 2019 recorded a ransomware attack, manual plant operations, and a refusal to pay.
DOJ and OCC records describe a web application firewall flaw and an over-broad cloud role, and the bank's shared-responsibility failure.
Special Publication 800-207 sets seven zero trust tenets and frames the shift as architectural, not a product purchase.
New York's financial regulator found vishing calls reached internal tools that more than 1,000 employees could use.
CISA's emergency directive, SolarWinds' SEC filing and Microsoft's investigation describe how a compromised build system spread.
OFAC's advisory says facilitating a ransomware payment can violate sanctions on a strict-liability basis, even without knowledge of the recipient.
CISA recorded active exploitation of CVE-2019-19781 from January 2020, before permanent fixes existed for every affected version.
CISA ordered federal domain controllers patched within days after a Netlogon flaw let an unauthenticated attacker seize admin rights.
UHS told investors it suspended IT access after a September 2020 incident, then said a month later it still could not quantify the cost.
An emergency directive followed mass web-shell exploitation of on-premises Exchange flaws Microsoft patched on 2 March 2021.
A precautionary IT shutdown halted East Coast fuel distribution after DarkSide ransomware hit the company's corporate network.
Executive Order 14028 set federal deadlines for zero trust, a software parts list and a standing incident review board.
JBS said it paid $11 million to prevent risk to customers, after restoring the bulk of its plants from its own defences.
A compromised remote-monitoring tool let attackers reach managed service providers and, through them, their customers.
BOD 22-01 requires federal agencies to patch by confirmed exploitation, not by CVSS score alone.
Log4j's fix arrived within days of disclosure; finding every place the library was embedded took much longer.
NTIA's minimum elements gave buyers and vendors a shared baseline for what a software bill of materials should include.
Conti ransomware forced a nationwide HSE shutdown; a related intrusion next door was caught and stopped in time.
Codecov's Bash Uploader was altered for two months to exfiltrate environment data from customers' build pipelines.
CISA's Conti advisory and a $15 million reward describe a ransomware operation that kept working after its internal chats went public.
The Cyber Safety Review Board's Lapsus$ report found SMS and voice MFA broadly insufficient and urged phishing-resistant sign-in.
A joint 2022 announcement describes what a passkey is meant to replace and what it does not address on its own.
A 2022 policy directs prosecutors to decline CFAA charges against good-faith security researchers, with conditions attached.
DOJ and FTC records show Joseph Sullivan concealed a 2016 Uber breach from the regulator investigating an earlier one.
LastPass's own notices describe how a stolen backup put encrypted vaults beyond the company's ability to protect them further.
Uber's security update describes repeated MFA push prompts wearing down a contractor until one login was approved.
CIRCIA set 72-hour incident and 24-hour ransom-payment reporting deadlines that do not take effect until CISA finalizes its rule.
Viasat and the UK government describe a management-network intrusion that disabled modems across Ukraine and Europe.
OpenSSL's own advisory explains why testing moved two certificate-parsing bugs from Critical to High before release.
A SQL injection in MOVEit Transfer let one group steal data from victims for months after the patch.
A signing key mishandled since 2021 let Storm-0558 forge tokens and reach government mailboxes, a review board found.
Caesars and MGM both disclosed 2023 breaches tied to IT help-desk deception, with different filings and outcomes.
The Biden administration's National Cybersecurity Strategy sought to rebalance responsibility toward the most capable defenders.
An SEC rule adopted in 2023 requires an 8-K within four business days of determining a cyber incident is material.
A compromised service account in Okta's support system let an attacker reach files customers uploaded for troubleshooting.
CVE-2023-4966 exposed valid NetScaler session cookies, and patching alone did not revoke ones already stolen.
CISA's Secure by Design guidance and pledge ask vendors to own customer security outcomes, with progress self-reported.
UnitedHealth's Senate testimony traces the Change Healthcare breach to one login without multi-factor authentication.
The NCA-led takedown captured LockBit's platform and keys, and Treasury later sanctioned its alleged administrator.
A CISA advisory and later reporting show the 2023 disruption degraded BlackCat without stopping ransomware as a service.
NIST's framework document explains what changed in 2024 and what the CSF still does not do.
A Microsoft engineer's investigation of a performance anomaly uncovered CVE-2024-3094 before it reached stable Linux.
Mandiant's investigation and Live Nation's own filing trace the 2024 campaign to credentials, not a platform breach.
The vendor's own root-cause analysis traces the July 2024 outage to a validation bug, not an intrusion.
Synnovis and the ICO describe how a lab supplier's outage delayed care and strained London's blood supply.
FIPS 203, 204 and 205 give organizations concrete algorithms to plan a cryptographic migration around.
A joint advisory assesses with high confidence that Volt Typhoon used built-in tools to sit inside critical infrastructure.
M&S, NCSC and NCA records describe a help-desk social-engineering wave across three retailers and the case for fast containment.
Google, Cloudflare and PagerDuty records show how stolen Drift OAuth tokens let an actor query Salesforce data across many companies.
F5's SEC filing and CISA's emergency directive describe a nation-state actor's long-term access to F5's build environment and stolen source code.
JLR's own statements, the NCSC and a government loan guarantee trace a shutdown that outlasted several announced restart dates.
GitHub and CISA describe a worm that used stolen maintainer tokens to publish malicious versions of hundreds of npm packages.
Microsoft and CISA documents describe a SharePoint patch bypass exploited before fixes existed for every on-premises version.
The Federal Register text of Executive Order 14306 shows exactly which 2025 cybersecurity duties were struck and which were kept.
The U.S. Code's own amendment history shows the 2015 information-sharing law's liability shield lapsed before Congress restored it.
SEC filings and a federal court's ruling trace the SolarWinds case from fraud charges to a 2025 dismissal with prejudice.
Operation Endgame's own record and a DOJ indictment describe a second coordinated strike on loader services, and a third five months later.
The directive expanded mandatory security duties to far more sectors, and enforcement began with member states, not companies.
The EU regulation applied from January 2025, requiring incident reporting, resilience testing and oversight of critical ICT providers.
Products with digital elements must be secure by design, and from September 2026 makers must report exploited flaws fast.
OMB rescinded the Biden-era attestation mandate but left the underlying framework and agencies' oversight duty in place.
BOD 26-04 replaces 2021's two-week and six-month clocks with urgency based on exposure and exploitability.
The March 2026 strategy is far shorter than 2023's and, unlike it, does not call for shifting liability to software makers.
Stryker's SEC filings describe a March 2026 IT disruption but stop short of the wiper and attribution outside researchers reported.
In March 2026, attackers compromised the Trivy and KICS scanning tools that other teams trust to find vulnerabilities.
A January 2025 memo ended the board's memberships while its Salt Typhoon review was still open, reporting says.
The largest pure cybersecurity acquisition closed in March 2026 after clearances from regulators on four continents.
CIS's 2021 rewrite grouped 153 safeguards into three implementation groups so smaller teams have a defined starting point.
SP 800-61 Revision 3 replaces a 2012 standalone guide with recommendations mapped to the Framework's six functions.
The ranking comes from contributed test data and a survey, and 94 percent of tested applications showed the flaw.
Since 2018, the paid, opt-in programme has released raw detection data rather than rankings, by design.
The widely cited average blends breach sizes and sectors, so it should not be read as a per-record multiplier.
IC3 recorded 859,532 complaints and 16.6 billion dollars in reported losses, a floor the report itself flags as low.
Police and vendors launched a joint decryptor catalogue in July 2016 that has grown well beyond its first four tools.
Revision 4 requires phishing-resistant authentication at higher assurance levels and bars synced keys from the top tier.
A contributed dataset showed third-party involvement in 48 percent of breaches, a figure with its own definitions and limits.
Coveware's payment rate keeps falling while Chainalysis's tracked total rose, and neither figure is a full ransomware count.
FireEye told the SEC a sophisticated actor took its red team tools and it built 300 countermeasures before any misuse was seen.
23andMe's DNA Relatives feature meant a small share of compromised accounts exposed data on many more relatives.
The Secure Future Initiative commits Microsoft to specific security goals, most of them still to be independently verified.
Try another category or clear your search.