Cyber History Calendar
A source-backed reference to the attacks, vulnerabilities, incidents, defensive milestones, regulatory changes, and technical turning points that shaped cybersecurity.
January
January event details
✣January 1986 — Brain boot-sector virus
Brain spread through infected floppy-disk boot sectors and is widely cited as the first IBM PC-compatible virus to circulate broadly.
Why it still matters: It marks malware’s transition from research curiosity to something that could spread through ordinary computer use.
▲January 2006 — WMF vulnerability crisis
A Windows Metafile vulnerability enabled drive-by exploitation through malicious images and triggered an out-of-cycle security update.
Why it still matters: Content-parsing flaws can create code-execution paths through routine web browsing.
▲January 3, 2018 — Meltdown and Spectre
Researchers disclosed speculative-execution attacks affecting modern processors.
Why it still matters: The flaws showed that security failures can exist below the operating system and require coordinated hardware and software fixes.
◆January 7, 2025 — PowerSchool breach publicly reported
PowerSchool disclosed unauthorized access to its student information system environment and data belonging to school districts.
Why it still matters: Concentrated education platforms hold sensitive data on students, parents, and staff and create broad downstream exposure when compromised.
▲January 10, 2024 — Ivanti Connect Secure zero-days
Ivanti disclosed critical vulnerabilities affecting Connect Secure and Policy Secure appliances that were being exploited.
Why it still matters: Internet-facing security appliances are prime initial-access targets and require rapid patching plus compromise assessment.
✣January 11, 2023 — Royal Mail ransomware incident
A ransomware incident disrupted Royal Mail’s international export services.
Why it still matters: Ransomware against logistics and postal systems can interrupt physical commerce and supply chains.
⊙January 12, 2010 — Operation Aurora disclosed
Google disclosed a sophisticated targeted intrusion that stole intellectual property and affected numerous large companies.
Why it still matters: Aurora was a watershed moment in public corporate disclosure of nation-state activity.
⊙January 13, 2022 — WhisperGate destructive malware
Microsoft described destructive malware targeting Ukrainian organizations and masquerading as ransomware.
Why it still matters: The campaign foreshadowed use of cyber operations alongside escalating geopolitical conflict.
★January 14, 2020 — Windows 7 end of support
Microsoft ended routine support for Windows 7.
Why it still matters: End-of-life operating systems become long-term security liabilities when organizations cannot retire or isolate them.
◆January 17, 2007 — TJX breach disclosed
TJX disclosed unauthorized access affecting payment-card and customer data across its retail operations.
Why it still matters: The breach became an early large-scale example of wireless security, card-data, and third-party risk failures.
✣January 25, 2003 — SQL Slammer
Slammer exploited a previously patched SQL Server flaw and caused a dramatic global traffic spike.
Why it still matters: It remains a classic example of how quickly a worm can weaponize a known vulnerability when patching lags.
✣January 26, 2004 — Mydoom
Mydoom spread through email and peer-to-peer networks, opened a backdoor, and launched denial-of-service activity.
Why it still matters: Compromised endpoints quickly became infrastructure for further attacks, a pattern still seen in botnets.
February
February event details
◎February 1995 — SSL 2.0 era begins
Netscape introduced SSL to protect web communications and support secure commercial use of the Internet.
Why it still matters: Encrypted web transport became a basic expectation for online trust, despite weaknesses in early versions.
◎February 2000 — Major Internet DDoS attacks
Distributed denial-of-service attacks disrupted major Internet properties including Yahoo, Amazon, CNN, and eBay.
Why it still matters: They demonstrated that even major online services could be overwhelmed through coordinated abuse of compromised systems.
✣February 2, 2023 — ESXiArgs campaign
Widespread ransomware exploitation targeted Internet-exposed VMware ESXi systems.
Why it still matters: Exposed virtualization infrastructure creates difficult recovery scenarios when hypervisors themselves are encrypted.
◆February 4, 2015 — Anthem breach disclosed
Anthem disclosed unauthorized access to a database containing information on current and former members and employees.
Why it still matters: Healthcare identity data has long-lived value and creates exposure that persists well beyond incident containment.
◆February 4, 2016 — Bangladesh Bank cyber heist
Attackers used compromised systems and fraudulent SWIFT messages in an attempt to steal nearly $1 billion from Bangladesh Bank.
Why it still matters: The heist showed how cyber compromise can manipulate trusted financial messaging and payment processes.
✣February 12, 2001 — Anna Kournikova worm
A social-engineering worm disguised as an image of tennis player Anna Kournikova spread widely through email.
Why it still matters: Compelling lures and trusted communication channels remain durable malware-delivery techniques.
§February 12, 2014 — NIST Cybersecurity Framework 1.0
NIST released the first Framework for Improving Critical Infrastructure Cybersecurity.
Why it still matters: The Framework created a common risk-based language for cybersecurity outcomes and executive communication.
✣February 16, 2016 — Hollywood Presbyterian ransomware payment
A hospital paid ransom after ransomware disrupted access to systems and records.
Why it still matters: Healthcare became one of the earliest sectors to show how ransomware could affect service delivery and patient-care operations.
⊙February 19, 2013 — Mandiant APT1 report
Mandiant published a detailed report linking a large cyber-espionage campaign to a unit of China’s People’s Liberation Army.
Why it still matters: The report helped normalize evidence-based public attribution of state-sponsored cyber operations.
▥February 21, 2024 — Change Healthcare cyberattack
UnitedHealth disclosed a cyberattack affecting Change Healthcare and disrupting claims, payments, pharmacy, and healthcare transactions.
Why it still matters: Concentration in a critical third-party platform can turn one compromise into a sector-wide operational problem.
▲February 23, 2017 — Cloudbleed
Cloudflare disclosed a memory-leak bug that could expose sensitive data from customer websites.
Why it still matters: Shared cloud and edge infrastructure bugs can create cross-tenant confidentiality risk.
⊙February 23, 2022 — HermeticWiper attacks
Destructive wiper malware was deployed against Ukrainian organizations immediately before Russia’s full-scale invasion.
Why it still matters: The campaign showed how destructive cyber operations can be integrated into broader military conflict.
§February 26, 2024 — NIST Cybersecurity Framework 2.0
NIST released CSF 2.0, expanding applicability and adding the Govern function.
Why it still matters: It formalized cybersecurity as an enterprise governance responsibility, not merely a technical function.
◎February 27, 2018 — GitHub 1.35 Tbps DDoS
GitHub experienced a record-setting DDoS attack amplified through exposed memcached servers.
Why it still matters: Misconfigured Internet infrastructure can be weaponized for enormous amplification attacks.
March
March event details
§March 1, 2017 — NYDFS Cybersecurity Regulation
New York’s cybersecurity regulation took effect for covered financial institutions.
Why it still matters: The rule helped normalize executive accountability, risk assessment, incident reporting, and program governance in financial services.
⊙March 2, 2021 — HAFNIUM / Exchange zero-days
Microsoft disclosed active exploitation of previously unknown Exchange Server vulnerabilities by a China-based threat actor it called HAFNIUM.
Why it still matters: Internet-facing messaging infrastructure became a direct path into enterprise networks.
▲March 14, 2017 — MS17-010 released
Microsoft fixed critical SMBv1 vulnerabilities including the flaw later associated with EternalBlue.
Why it still matters: Organizations had nearly two months to patch before WannaCry weaponized the flaw at global scale.
⌘March 17, 2011 — RSA SecurID breach disclosed
RSA disclosed an advanced persistent threat and warned that information related to SecurID products had been extracted.
Why it still matters: Security controls with privileged trust relationships are strategic targets in their own right.
§March 17, 2018 — Cambridge Analytica scandal breaks widely
Reporting revealed large-scale harvesting and political use of Facebook user data through a third-party app ecosystem.
Why it still matters: The scandal accelerated scrutiny of platform data governance, consent, third-party access, and privacy accountability.
✣March 19, 2019 — Norsk Hydro ransomware attack
Norsk Hydro suffered a ransomware attack that disrupted global operations and forced substantial manual processing.
Why it still matters: Its response became a widely cited example of transparent crisis communication and resilience.
⊙March 20, 2013 — DarkSeoul attacks
Cyberattacks disrupted major South Korean banks and broadcasters, wiping systems and affecting operations.
Why it still matters: The incident showed how destructive malware can be used for national-level disruption.
⌘March 22, 2022 — Okta / LAPSUS$ incident disclosed
Okta disclosed details around a third-party support engineer compromise after LAPSUS$ published screenshots suggesting access.
Why it still matters: The incident highlighted identity-provider concentration and privileged third-party support risk.
⌘March 23, 2011 — Comodo certificate compromise
A certificate-authority reseller account was compromised and used to issue fraudulent certificates for major online services.
Why it still matters: Web trust depends on the operational security of certificate-issuance infrastructure, not cryptography alone.
✣March 26, 1999 — Melissa
Melissa spread through infected Word documents and Outlook address books, disrupting enterprise mail systems.
Why it still matters: Attackers still win by abusing trust, familiar file formats, and legitimate communication channels.
↗March 29, 2023 — 3CX supply-chain compromise
A trojanized 3CX desktop application was used in a supply-chain attack affecting downstream customers.
Why it still matters: Trusted signed software can become an attack-delivery channel when development or build environments are compromised.
↗March 29, 2024 — XZ Utils backdoor
A sophisticated backdoor was discovered in XZ Utils 5.6.0 and 5.6.1 after malicious code entered upstream release tarballs.
Why it still matters: Patient compromise of an open-source project can create risk far beyond the original repository.
▲March 31, 2022 — Spring4Shell
A critical Spring Framework vulnerability could enable unauthenticated remote code execution under affected configurations.
Why it still matters: It reinforced the challenge of rapidly understanding application-framework exposure across large software estates.
April
April event details
✣April 2002 — Klez worm surge
Klez became a widespread email worm, spoofing sender addresses and distributing infected attachments.
Why it still matters: Sender spoofing and trusted-channel abuse remain basic ingredients of modern social engineering.
✣April 6, 2022 — Costa Rica ransomware crisis
Conti ransomware attacks disrupted multiple Costa Rican government agencies and public services.
Why it still matters: The crisis showed ransomware reaching a level where a national government declared an emergency.
▲April 7, 2014 — Heartbleed
Heartbleed exposed a flaw in OpenSSL heartbeat handling that allowed remote attackers to read portions of process memory.
Why it still matters: It showed how one defect in a ubiquitous security library can create global risk and require key rotation beyond patching.
▲April 12, 2024 — PAN-OS CVE-2024-3400 disclosed
Palo Alto Networks disclosed a critical command-injection vulnerability affecting GlobalProtect on certain PAN-OS configurations.
Why it still matters: Security perimeter devices can become privileged attack paths when Internet-facing components are exploitable.
▲April 14, 2017 — EternalBlue exploit released publicly
The Shadow Brokers released offensive tooling including EternalBlue.
Why it still matters: Public release of weaponized exploit code dramatically shortened the path from vulnerability to widespread criminal use.
✣April 26, 1999 — CIH / Chernobyl virus
CIH overwrote hard-drive data and, on some systems, flash BIOS content when it activated.
Why it still matters: It is an early example of malware designed for destructive impact beyond nuisance or propagation.
◆April 26, 2011 — PlayStation Network breach disclosed
Sony disclosed a major compromise of PlayStation Network and Qriocity user data after taking services offline.
Why it still matters: The incident highlighted large-scale consumer identity exposure and the operational cost of prolonged outages.
⊙April 27, 2007 — Estonia cyberattacks begin
Estonian government, banking, media, and other online services experienced sustained disruptive cyber activity amid political tensions.
Why it still matters: The attacks became a landmark case in national cyber defense, resilience, and geopolitical cyber disruption.
May
May event details
✣May 1, 2004 — Sasser
Sasser exploited the Windows LSASS vulnerability and could propagate without a user opening an attachment.
Why it still matters: It reinforced the risk of rapid exploitation following vulnerability disclosure.
◆May 2024 — Snowflake customer compromises emerge
A campaign involving stolen customer credentials affected multiple organizations using Snowflake-hosted data environments.
Why it still matters: Shared cloud platforms amplify the importance of MFA, credential hygiene, and identity logging.
✣May 4, 2000 — ILOVEYOU / Love Letter worm
The Love Letter worm spread through a malicious Visual Basic Script attachment and automated forwarding.
Why it still matters: It combined human psychology with automated propagation, a pattern still visible in modern phishing and malware delivery.
✣May 7, 2019 — Baltimore ransomware attack
Baltimore city systems were disrupted by ransomware, affecting email, property transactions, billing, and municipal services.
Why it still matters: Ransomware can become a public-service continuity problem, not merely an IT outage.
▥May 7, 2021 — Colonial Pipeline ransomware
Colonial Pipeline experienced a network disruption that led to shutdown of pipeline operations; the FBI later confirmed DarkSide ransomware.
Why it still matters: A business-system compromise can create physical-world consequences when operations are shut down for safety or containment.
✣May 12, 2017 — WannaCry
WannaCry spread globally by exploiting an SMB vulnerability Microsoft had patched two months earlier.
Why it still matters: It remains a defining example of the cost of delayed patching, unsupported systems, and flat networks.
▲May 14, 2019 — BlueKeep
Microsoft released fixes for a pre-authentication remote-code-execution vulnerability in Remote Desktop Services and warned it was wormable.
Why it still matters: BlueKeep reinforced the danger of exposed remote administration and end-of-life systems.
§May 25, 2018 — GDPR becomes applicable
The EU General Data Protection Regulation became applicable across member states.
Why it still matters: GDPR materially changed the global privacy landscape and made data governance, security, and privacy inseparable executive concerns.
⊙May 28, 2012 — Flame malware revealed
Researchers disclosed Flame, a sophisticated espionage platform used primarily in the Middle East.
Why it still matters: Flame illustrated the growing complexity and modularity of state-aligned cyber espionage tooling.
✣May 30, 2021 — JBS ransomware attack
JBS experienced a ransomware attack that disrupted meat-processing operations in multiple countries.
Why it still matters: Ransomware against concentrated suppliers can create broader economic and supply-chain risk.
↗May 31, 2023 — MOVEit zero-day disclosed
Progress Software released patches for a critical MOVEit Transfer vulnerability after signs of active exploitation.
Why it still matters: One widely used file-transfer product created cascading third-party data exposure across many organizations.
◆May 31, 2024 — Live Nation / Ticketmaster cloud incident
Live Nation disclosed unauthorized activity in a third-party cloud database environment containing company data including Ticketmaster information.
Why it still matters: The incident highlighted third-party cloud concentration and the use of stolen credentials against SaaS and data platforms.
June
June event details
§June 1990 — UK Computer Misuse Act
The United Kingdom enacted the Computer Misuse Act, creating criminal offenses for unauthorized access and related computer misuse.
Why it still matters: It became a foundational cybercrime statute and still shapes debates over authorization and security research.
◆June 4, 2015 — OPM breach announced
The U.S. Office of Personnel Management disclosed a major incident affecting federal personnel and background-investigation data.
Why it still matters: The breach demonstrated the intelligence value of aggregated identity and personnel information.
◆June 6, 2012 — LinkedIn password breach
Millions of hashed LinkedIn passwords were posted online following a breach.
Why it still matters: The incident reinforced the importance of strong password hashing, unique credentials, and resistance to credential reuse.
⊙June 14, 2016 — DNC intrusion disclosed
The Democratic National Committee disclosed a network compromise attributed by investigators to Russian intelligence-linked groups.
Why it still matters: The incident became a landmark example of cyber-enabled information operations intersecting with political processes.
▥June 17, 2010 — Stuxnet first identified
Security researchers identified malware later shown to target specific industrial-control environments.
Why it still matters: Its discovery marked a turning point in awareness of cyber weapons designed to manipulate physical processes.
↗June 26, 2024 — Polyfill.io compromise
Cloudflare reported that the popular polyfill.io JavaScript service could no longer be trusted after malicious code injection.
Why it still matters: Externally hosted client-side dependencies can silently become supply-chain channels into huge numbers of websites.
↗June 27, 2017 — NotPetya
NotPetya spread from compromised Ukrainian software into organizations around the world and functioned primarily as destructive malware.
Why it still matters: It remains a textbook example of a targeted supply-chain compromise creating enormous unintended blast radius.
§June 28, 2018 — CCPA signed
California enacted the Consumer Privacy Act, creating new rights around access, deletion, disclosure, and sale of personal information.
Why it still matters: CCPA helped establish a U.S. state-level privacy model that influenced subsequent legislation.
July
July event details
★July 1993 — First DEF CON
The first DEF CON brought hackers, researchers, and security practitioners together in Las Vegas.
Why it still matters: DEF CON became one of the most influential forums for practical security research and hacker culture.
▲July 1, 2021 — PrintNightmare
Critical Windows Print Spooler vulnerabilities and public exploit code drew widespread attention.
Why it still matters: Legacy services can create high-impact enterprise attack paths, and disclosure confusion can complicate remediation.
▲July 1, 2024 — regreSSHion
Qualys disclosed an unauthenticated remote-code-execution vulnerability in OpenSSH server on affected glibc-based Linux systems.
Why it still matters: Fixed vulnerabilities can return through code changes; regression testing matters even for mature infrastructure software.
↗July 2, 2021 — Kaseya VSA ransomware attack
A ransomware campaign exploited Kaseya VSA and affected managed service providers and downstream customers.
Why it still matters: Management platforms offer attackers enormous leverage because one compromise can cascade into many customers.
⊙July 4, 2009 — U.S. and South Korea DDoS attacks
Government, financial, and media websites in the United States and South Korea were targeted by coordinated denial-of-service attacks.
Why it still matters: The campaign reinforced the use of botnets for politically significant disruption and the difficulty of attribution.
▲July 8, 2008 — Kaminsky DNS flaw disclosed
Dan Kaminsky disclosed a fundamental DNS cache-poisoning weakness after a coordinated multi-vendor patch effort.
Why it still matters: The episode showed the systemic risk of flaws in core Internet infrastructure and the value of coordinated disclosure.
◆July 8, 2015 — Hacking Team breach
Hacking Team’s internal data and source code were leaked following a compromise.
Why it still matters: The breach exposed the commercial offensive-security ecosystem and fueled debate over zero-day markets and surveillance technology.
⌘July 15, 2020 — Twitter account takeover
Attackers compromised internal tools and took over numerous high-profile Twitter accounts to promote a cryptocurrency scam.
Why it still matters: Privileged support workflows can bypass strong user-facing security controls.
✣July 19, 2001 — Code Red
Code Red exploited a vulnerability in Microsoft IIS and infected hundreds of thousands of Internet-facing systems.
Why it still matters: Self-propagating attacks against exposed infrastructure can move faster than human remediation processes.
◎July 19, 2024 — CrowdStrike Channel File 291 outage
A CrowdStrike content configuration update triggered Windows system crashes at global scale; CrowdStrike said it was not a cyberattack.
Why it still matters: The outage demonstrated concentration risk in security tooling and the importance of staged deployment, rollback, validation, and resilience.
◆July 20, 2015 — Ashley Madison breach disclosed
Attackers disclosed a compromise of Ashley Madison and later released stolen user data.
Why it still matters: The incident highlighted the personal, legal, and reputational consequences of breaches involving highly sensitive behavioral data.
◆July 20, 2018 — SingHealth breach disclosed
Singapore disclosed theft of personal data belonging to about 1.5 million SingHealth patients.
Why it still matters: Healthcare data has long-term intelligence and identity-abuse value, not merely immediate financial value.
✣July 23, 2020 — Garmin ransomware outage
Garmin experienced a major outage affecting online services, support, and connected-device synchronization following ransomware.
Why it still matters: Ransomware can disrupt both enterprise operations and customer-facing connected services.
§July 26, 2023 — SEC cybersecurity disclosure rules
The SEC adopted rules requiring public companies to disclose material cyber incidents and annual information about risk management and governance.
Why it still matters: Cybersecurity materiality and governance became explicit securities-law concerns for public companies.
◆July 29, 2019 — Capital One breach announced
Capital One disclosed unauthorized access to personal information associated with credit-card applications and customers.
Why it still matters: The breach became a cloud-security case study in configuration, identity, metadata services, and least privilege.
August
August event details
§August 1, 2024 — EU AI Act enters into force
The European Union’s AI Act entered into force, establishing a risk-based legal framework for artificial intelligence systems.
Why it still matters: AI governance became a formal compliance discipline increasingly intersecting with cybersecurity, privacy, and digital trust.
✣August 3, 1998 — Back Orifice released
Cult of the Dead Cow released Back Orifice, a remote-administration tool that could covertly control Windows systems.
Why it still matters: It popularized the concept of remote-access trojans and abuse of legitimate administration functions.
✣August 11, 2003 — Blaster worm
Blaster exploited a previously patched Windows RPC vulnerability and scanned continuously for additional vulnerable hosts.
Why it still matters: It illustrates the persistent gap between patch availability and actual remediation.
⊙August 13, 2016 — Shadow Brokers leaks begin
The Shadow Brokers published tools and exploits allegedly associated with the Equation Group.
Why it still matters: Leakage of high-end offensive tooling can rapidly convert state-developed capabilities into broad criminal attack risk.
✣August 14, 2005 — Zotob worm
Zotob exploited a recently disclosed Windows Plug and Play vulnerability and disrupted corporate and media networks.
Why it still matters: It showed how quickly exploit code can follow a patch and why emergency vulnerability management matters.
▥August 15, 2012 — Shamoon attacks Saudi Aramco
Shamoon was used in a destructive attack that wiped large numbers of Saudi Aramco workstations.
Why it still matters: The attack demonstrated the business impact of destructive malware and the importance of segmentation and recovery.
✣August 18, 2003 — Sobig.F
Sobig.F spread through email at enormous scale and generated significant mail disruption.
Why it still matters: Mass-mailing malware showed how compromised endpoints could become infrastructure for large-scale abuse.
⌘August 25, 2022 — LastPass development-environment breach
LastPass disclosed unauthorized access to portions of its development environment through a compromised developer account.
Why it still matters: Technical information and developer access can become building blocks for follow-on compromise.
⌘August 29, 2011 — DigiNotar fraudulent certificates exposed
Fraudulent certificates issued after compromise of DigiNotar were discovered, ultimately destroying trust in the certificate authority.
Why it still matters: Compromise of one PKI trust anchor can create ecosystem-wide consequences.
September
September event details
★September 1999 — CVE initiative launched
MITRE launched Common Vulnerabilities and Exposures to give publicly known vulnerabilities standardized identifiers.
Why it still matters: CVE created a shared language for vulnerability management across vendors, scanners, advisories, and defenders.
◆September 2023 — Caesars Entertainment cyber incident
Caesars disclosed a cyber incident involving theft of loyalty-program customer data and payment to attackers.
Why it still matters: The event reinforced the value of identity data and the role of social engineering in hospitality attacks.
⊙September 2024 — Salt Typhoon telecom intrusions become public
Reports described a China-linked campaign compromising major telecommunications providers and sensitive communications infrastructure.
Why it still matters: Telecom infrastructure is strategic because compromise can provide access to communications, metadata, and intelligence collection.
◆September 7, 2017 — Equifax breach announced
Equifax disclosed a major incident involving highly sensitive consumer identity data.
Why it still matters: It became a defining case for vulnerability management, data concentration, executive accountability, and identity risk.
◆September 8, 2014 — Home Depot breach disclosed
Home Depot disclosed a payment-card breach involving malware on point-of-sale systems.
Why it still matters: Retail breaches reinforced the need for segmentation, payment-environment hardening, and third-party access controls.
▥September 10, 2020 — Düsseldorf hospital ransomware incident
A ransomware incident disrupted systems at a German hospital and was associated with diversion of an emergency patient.
Why it still matters: Cyber incidents in healthcare can create real-world safety consequences.
◆September 12, 2023 — MGM Resorts cyber incident
MGM Resorts disclosed a cybersecurity issue affecting U.S. systems and significant property operations.
Why it still matters: The event showed how identity compromise and containment can rapidly become visible business-operations problems.
⌘September 15, 2022 — Uber intrusion
Uber disclosed a security incident after an attacker gained broad internal access using social engineering and compromised credentials.
Why it still matters: The incident reinforced the importance of phishing-resistant authentication and privileged-access segmentation.
✣September 18, 2001 — Nimda
Nimda spread through email, network shares, compromised websites, vulnerable IIS servers, and earlier backdoors.
Why it still matters: It demonstrated the danger of combining multiple propagation vectors into one campaign.
◆September 22, 2022 — Optus breach
Australian telecom provider Optus disclosed a major breach involving customer identity information.
Why it still matters: Telecommunications providers are high-value targets because they combine identity, account, device, and communications data.
▲September 24, 2014 — Shellshock
Shellshock allowed arbitrary command execution through crafted environment variables processed by GNU Bash.
Why it still matters: It demonstrated the systemic risk created when foundational components are embedded across enormous software estates.
▥September 29, 2010 — ICS-CERT Stuxnet advisory
ICS-CERT documented Stuxnet targeting Siemens industrial-control software and using multiple advanced propagation techniques.
Why it still matters: Stuxnet permanently changed the conversation around cyber-physical risk.
October
October event details
◆October 2, 2014 — JPMorgan Chase breach disclosed
JPMorgan Chase disclosed a major intrusion affecting contact information associated with tens of millions of households and small businesses.
Why it still matters: The incident underscored the scale and attractiveness of identity data held by financial institutions.
◆October 3, 2013 — Adobe breach disclosed
Adobe disclosed an intrusion involving customer information and source code.
Why it still matters: The breach illustrated the value attackers place on both identity data and proprietary software source code.
▲October 10, 2023 — Citrix Bleed
Citrix released updates for a NetScaler vulnerability later associated with session-token theft and session hijacking.
Why it still matters: Patching alone may not terminate attacker access obtained before remediation; session invalidation can also be required.
◆October 13, 2022 — Medibank cyber incident
Australian health insurer Medibank disclosed an incident that later involved theft and publication of highly sensitive customer data.
Why it still matters: Health and claims data can create extreme privacy harm when stolen and used for extortion.
▲October 14, 2014 — POODLE disclosed
Researchers disclosed a weakness in SSL 3.0 that could allow recovery of plaintext from encrypted connections.
Why it still matters: Legacy compatibility can preserve attack paths long after stronger replacements exist.
▲October 16, 2017 — KRACK disclosed
Researchers disclosed key reinstallation attacks against WPA2.
Why it still matters: Even mature, ubiquitous security protocols can fail through subtle state-machine and implementation flaws.
§October 17, 2024 — NIS2 transposition deadline
EU member states reached the deadline for transposing the NIS2 Directive into national law.
Why it still matters: NIS2 raised expectations for governance, supply-chain security, incident reporting, and executive accountability.
⌘October 20, 2023 — Okta support-system breach
Okta disclosed unauthorized access to its customer support case-management system using a stolen credential.
Why it still matters: Identity providers sit at a uniquely sensitive trust boundary, including supporting systems and uploaded troubleshooting artifacts.
◎October 21, 2016 — Mirai / Dyn DDoS attack
A massive DDoS attack targeted DNS provider Dyn using the Mirai botnet, disrupting access to major online services.
Why it still matters: The attack made insecure IoT devices part of the global threat model and highlighted DNS as critical shared infrastructure.
▲October 23, 2008 — MS08-067 emergency patch
Microsoft issued an out-of-band critical update for a remotely exploitable Windows Server service vulnerability.
Why it still matters: The flaw was later exploited by Conficker and remains a classic emergency-patching case.
§October 30, 2023 — SEC charges SolarWinds and CISO
The SEC filed civil charges against SolarWinds and its CISO alleging fraud and internal-control failures related to cybersecurity disclosures.
Why it still matters: The case intensified scrutiny of executive cybersecurity statements, disclosure controls, and personal accountability.
November
November event details
▲November 1, 2022 — OpenSSL CVE-2022-3602 / 3786
OpenSSL released fixes for certificate-parsing vulnerabilities that drew broad attention because of the library’s ubiquity.
Why it still matters: The episode reinforced the need for rapid dependency inventory when shared libraries are affected.
✣November 2, 1988 — Morris Worm
The Morris Worm spread rapidly across the early Internet, exploiting multiple weaknesses and affecting thousands of systems.
Why it still matters: It became a foundational Internet security incident and helped drive organized incident-response capability.
★November 3, 2021 — CISA Known Exploited Vulnerabilities catalog
CISA issued BOD 22-01 and operationalized the Known Exploited Vulnerabilities catalog for federal remediation prioritization.
Why it still matters: It helped shift vulnerability management toward exploitation evidence and real-world risk rather than severity scores alone.
★November 10, 1983 — Fred Cohen virus demonstration
Fred Cohen demonstrated self-replicating code during academic security research, helping formalize the modern computer-virus concept.
Why it still matters: It helped turn malicious self-replication into a defined computer-security problem.
★November 16, 2018 — CISA established
The Cybersecurity and Infrastructure Security Agency Act formally established CISA.
Why it still matters: CISA became the central U.S. civilian agency for cyber defense, critical-infrastructure security, and vulnerability coordination.
★November 17, 1988 — CERT Coordination Center established
DARPA funded creation of the CERT Coordination Center at Carnegie Mellon after the Morris Worm.
Why it still matters: Modern incident coordination and vulnerability-response practices trace directly to needs exposed by early Internet-wide incidents.
✣November 21, 2008 — Conficker discovered
Conficker exploited the Windows Server service vulnerability addressed by MS08-067 and added multiple propagation techniques.
Why it still matters: It showed how unpatched systems, weak credentials, removable media, and shares can combine into durable malware spread.
◆November 21, 2017 — Uber breach disclosed
Uber disclosed a 2016 breach involving personal data for millions of riders and drivers and acknowledged paying the attackers.
Why it still matters: The incident became a governance case study in breach disclosure, extortion, and executive accountability.
◆November 24, 2014 — Sony Pictures destructive attack
Sony Pictures suffered a destructive intrusion involving malware, stolen data, and major operational disruption.
Why it still matters: The attack showed how theft, coercion, public disclosure, and destruction can be combined in one campaign.
◆November 30, 2018 — Marriott / Starwood breach disclosed
Marriott announced unauthorized access to the Starwood reservation database involving a large volume of guest data.
Why it still matters: The incident highlighted acquisition due diligence, inherited technology risk, data retention, and long attacker dwell time.
December
December event details
✣December 1989 — AIDS Trojan / PC Cyborg
The AIDS Trojan was distributed on floppy disks, hid directories, encrypted filenames, and demanded payment by postal mail.
Why it still matters: Often cited as the first ransomware, it proves the extortion model predates cryptocurrency by decades.
§December 2004 — PCI DSS 1.0
Major payment-card brands created the first Payment Card Industry Data Security Standard.
Why it still matters: PCI DSS became one of the most influential industry security compliance baselines.
◆December 2008 — Heartland Payment Systems breach discovered
Heartland discovered a major payment-card breach involving malware in transaction-processing systems.
Why it still matters: The case became an important milestone in payment-security accountability and processor risk.
◆December 8, 2020 — FireEye breach disclosed
FireEye disclosed that a sophisticated actor stole proprietary Red Team assessment tools.
Why it still matters: The incident showed the value attackers place on security tooling and the need for rapid public defensive action after compromise.
▲December 10, 2021 — Log4Shell
Log4Shell exposed remote-code-execution risk in widely deployed Apache Log4j versions through JNDI lookup behavior.
Why it still matters: It showed how hidden software dependencies can become enterprise-wide security emergencies.
§December 10, 2024 — EU Cyber Resilience Act enters into force
The Cyber Resilience Act entered into force, establishing cybersecurity requirements for products with digital elements.
Why it still matters: It moves software and hardware security toward lifecycle duty of care, secure-by-design expectations, and manufacturer accountability.
↗December 13, 2020 — SolarWinds Orion compromise
CISA warned of active exploitation involving compromised SolarWinds Orion releases delivered through trusted updates.
Why it still matters: SolarWinds changed how boards and security teams think about software supply chains and privileged management platforms.
◆December 19, 2013 — Target breach announced
Target confirmed unauthorized access to payment-card data affecting tens of millions of accounts.
Why it still matters: The breach became a landmark example of third-party access risk, point-of-sale compromise, and executive accountability.
▥December 23, 2015 — Ukraine power grid cyberattack
A coordinated cyber operation disrupted electricity distribution in Ukraine through enterprise compromise and control-system access.
Why it still matters: It became one of the defining examples of cyber operations causing real-world critical-infrastructure disruption.
Cyber history, month by month
The XML corpus currently contains 133 records. Each row includes the historical date, event type, substantive context, why it still matters, and available source material.
Cyber history as a living reference.
The event corpus is maintained separately in structured XML. This page is the presentation layer. The XML can continue growing without changing the visual taxonomy or editorial standard.
The next integration step is hosting the XML at a stable web endpoint so the page can query it dynamically without relying on inline script execution inside WordPress content.
Editorial standard
Primary and authoritative sources are preferred. Wikipedia is useful background and discovery, not a substitute for stronger evidence when available.