LONGO.ORG • CYBER HISTORY

Cyber History Calendar

The past informs a more secure future.

A source-backed reference to the attacks, vulnerabilities, incidents, defensive milestones, regulatory changes, and technical turning points that shaped cybersecurity.

Source-backed XML • Standards-based calendar feed

January

12 historical events in the repository

Also this month: ✣ Brain boot-sector virus (1986)  •  ▲ WMF vulnerability crisis (2006)
Sun
Mon
Tue
Wed
Thu
Fri
Sat
1
2
3
▲Meltdown and Spectre (2018)
4
5
6
7
◆PowerSchool breach publicly reported (2025)
8
9
10
▲Ivanti Connect Secure zero-days (2024)
11
✣Royal Mail ransomware incident (2023)
12
⊙Operation Aurora disclosed (2010)
13
⊙WhisperGate destructive malware (2022)
14
★Windows 7 end of support (2020)
15
16
17
◆TJX breach disclosed (2007)
18
19
20
21
22
23
24
25
✣SQL Slammer (2003)
26
✣Mydoom (2004)
27
28
29
30
31

January event details

✣January 1986 — Brain boot-sector virus

Brain spread through infected floppy-disk boot sectors and is widely cited as the first IBM PC-compatible virus to circulate broadly.

Why it still matters: It marks malware’s transition from research curiosity to something that could spread through ordinary computer use.

▲January 2006 — WMF vulnerability crisis

A Windows Metafile vulnerability enabled drive-by exploitation through malicious images and triggered an out-of-cycle security update.

Why it still matters: Content-parsing flaws can create code-execution paths through routine web browsing.

▲January 3, 2018 — Meltdown and Spectre

Researchers disclosed speculative-execution attacks affecting modern processors.

Why it still matters: The flaws showed that security failures can exist below the operating system and require coordinated hardware and software fixes.

◆January 7, 2025 — PowerSchool breach publicly reported

PowerSchool disclosed unauthorized access to its student information system environment and data belonging to school districts.

Why it still matters: Concentrated education platforms hold sensitive data on students, parents, and staff and create broad downstream exposure when compromised.

▲January 10, 2024 — Ivanti Connect Secure zero-days

Ivanti disclosed critical vulnerabilities affecting Connect Secure and Policy Secure appliances that were being exploited.

Why it still matters: Internet-facing security appliances are prime initial-access targets and require rapid patching plus compromise assessment.

✣January 11, 2023 — Royal Mail ransomware incident

A ransomware incident disrupted Royal Mail’s international export services.

Why it still matters: Ransomware against logistics and postal systems can interrupt physical commerce and supply chains.

⊙January 12, 2010 — Operation Aurora disclosed

Google disclosed a sophisticated targeted intrusion that stole intellectual property and affected numerous large companies.

Why it still matters: Aurora was a watershed moment in public corporate disclosure of nation-state activity.

⊙January 13, 2022 — WhisperGate destructive malware

Microsoft described destructive malware targeting Ukrainian organizations and masquerading as ransomware.

Why it still matters: The campaign foreshadowed use of cyber operations alongside escalating geopolitical conflict.

★January 14, 2020 — Windows 7 end of support

Microsoft ended routine support for Windows 7.

Why it still matters: End-of-life operating systems become long-term security liabilities when organizations cannot retire or isolate them.

◆January 17, 2007 — TJX breach disclosed

TJX disclosed unauthorized access affecting payment-card and customer data across its retail operations.

Why it still matters: The breach became an early large-scale example of wireless security, card-data, and third-party risk failures.

✣January 25, 2003 — SQL Slammer

Slammer exploited a previously patched SQL Server flaw and caused a dramatic global traffic spike.

Why it still matters: It remains a classic example of how quickly a worm can weaponize a known vulnerability when patching lags.

✣January 26, 2004 — Mydoom

Mydoom spread through email and peer-to-peer networks, opened a backdoor, and launched denial-of-service activity.

Why it still matters: Compromised endpoints quickly became infrastructure for further attacks, a pattern still seen in botnets.

February

14 historical events in the repository

Also this month: ◎ SSL 2.0 era begins (1995)  •  ◎ Major Internet DDoS attacks (2000)
Sun
Mon
Tue
Wed
Thu
Fri
Sat
1
2
✣ESXiArgs campaign (2023)
3
4
◆Anthem breach disclosed (2015)
◆Bangladesh Bank cyber heist (2016)
5
6
7
8
9
10
11
12
✣Anna Kournikova worm (2001)
§NIST Cybersecurity Framework 1.0 (2014)
13
14
15
16
✣Hollywood Presbyterian ransomware payment (2016)
17
18
19
⊙Mandiant APT1 report (2013)
20
21
▥Change Healthcare cyberattack (2024)
22
23
▲Cloudbleed (2017)
⊙HermeticWiper attacks (2022)
24
25
26
§NIST Cybersecurity Framework 2.0 (2024)
27
◎GitHub 1.35 Tbps DDoS (2018)
28

February event details

◎February 1995 — SSL 2.0 era begins

Netscape introduced SSL to protect web communications and support secure commercial use of the Internet.

Why it still matters: Encrypted web transport became a basic expectation for online trust, despite weaknesses in early versions.

◎February 2000 — Major Internet DDoS attacks

Distributed denial-of-service attacks disrupted major Internet properties including Yahoo, Amazon, CNN, and eBay.

Why it still matters: They demonstrated that even major online services could be overwhelmed through coordinated abuse of compromised systems.

✣February 2, 2023 — ESXiArgs campaign

Widespread ransomware exploitation targeted Internet-exposed VMware ESXi systems.

Why it still matters: Exposed virtualization infrastructure creates difficult recovery scenarios when hypervisors themselves are encrypted.

◆February 4, 2015 — Anthem breach disclosed

Anthem disclosed unauthorized access to a database containing information on current and former members and employees.

Why it still matters: Healthcare identity data has long-lived value and creates exposure that persists well beyond incident containment.

◆February 4, 2016 — Bangladesh Bank cyber heist

Attackers used compromised systems and fraudulent SWIFT messages in an attempt to steal nearly $1 billion from Bangladesh Bank.

Why it still matters: The heist showed how cyber compromise can manipulate trusted financial messaging and payment processes.

✣February 12, 2001 — Anna Kournikova worm

A social-engineering worm disguised as an image of tennis player Anna Kournikova spread widely through email.

Why it still matters: Compelling lures and trusted communication channels remain durable malware-delivery techniques.

§February 12, 2014 — NIST Cybersecurity Framework 1.0

NIST released the first Framework for Improving Critical Infrastructure Cybersecurity.

Why it still matters: The Framework created a common risk-based language for cybersecurity outcomes and executive communication.

✣February 16, 2016 — Hollywood Presbyterian ransomware payment

A hospital paid ransom after ransomware disrupted access to systems and records.

Why it still matters: Healthcare became one of the earliest sectors to show how ransomware could affect service delivery and patient-care operations.

⊙February 19, 2013 — Mandiant APT1 report

Mandiant published a detailed report linking a large cyber-espionage campaign to a unit of China’s People’s Liberation Army.

Why it still matters: The report helped normalize evidence-based public attribution of state-sponsored cyber operations.

▥February 21, 2024 — Change Healthcare cyberattack

UnitedHealth disclosed a cyberattack affecting Change Healthcare and disrupting claims, payments, pharmacy, and healthcare transactions.

Why it still matters: Concentration in a critical third-party platform can turn one compromise into a sector-wide operational problem.

▲February 23, 2017 — Cloudbleed

Cloudflare disclosed a memory-leak bug that could expose sensitive data from customer websites.

Why it still matters: Shared cloud and edge infrastructure bugs can create cross-tenant confidentiality risk.

⊙February 23, 2022 — HermeticWiper attacks

Destructive wiper malware was deployed against Ukrainian organizations immediately before Russia’s full-scale invasion.

Why it still matters: The campaign showed how destructive cyber operations can be integrated into broader military conflict.

§February 26, 2024 — NIST Cybersecurity Framework 2.0

NIST released CSF 2.0, expanding applicability and adding the Govern function.

Why it still matters: It formalized cybersecurity as an enterprise governance responsibility, not merely a technical function.

◎February 27, 2018 — GitHub 1.35 Tbps DDoS

GitHub experienced a record-setting DDoS attack amplified through exposed memcached servers.

Why it still matters: Misconfigured Internet infrastructure can be weaponized for enormous amplification attacks.

March

13 historical events in the repository

Sun
Mon
Tue
Wed
Thu
Fri
Sat
1
§NYDFS Cybersecurity Regulation (2017)
2
⊙HAFNIUM / Exchange zero-days (2021)
3
4
5
6
7
8
9
10
11
12
13
14
▲MS17-010 released (2017)
15
16
17
⌘RSA SecurID breach disclosed (2011)
§Cambridge Analytica scandal breaks widely (2018)
18
19
✣Norsk Hydro ransomware attack (2019)
20
⊙DarkSeoul attacks (2013)
21
22
⌘Okta / LAPSUS$ incident disclosed (2022)
23
⌘Comodo certificate compromise (2011)
24
25
26
✣Melissa (1999)
27
28
29
↗3CX supply-chain compromise (2023)
↗XZ Utils backdoor (2024)
30
31
▲Spring4Shell (2022)

March event details

§March 1, 2017 — NYDFS Cybersecurity Regulation

New York’s cybersecurity regulation took effect for covered financial institutions.

Why it still matters: The rule helped normalize executive accountability, risk assessment, incident reporting, and program governance in financial services.

⊙March 2, 2021 — HAFNIUM / Exchange zero-days

Microsoft disclosed active exploitation of previously unknown Exchange Server vulnerabilities by a China-based threat actor it called HAFNIUM.

Why it still matters: Internet-facing messaging infrastructure became a direct path into enterprise networks.

▲March 14, 2017 — MS17-010 released

Microsoft fixed critical SMBv1 vulnerabilities including the flaw later associated with EternalBlue.

Why it still matters: Organizations had nearly two months to patch before WannaCry weaponized the flaw at global scale.

⌘March 17, 2011 — RSA SecurID breach disclosed

RSA disclosed an advanced persistent threat and warned that information related to SecurID products had been extracted.

Why it still matters: Security controls with privileged trust relationships are strategic targets in their own right.

§March 17, 2018 — Cambridge Analytica scandal breaks widely

Reporting revealed large-scale harvesting and political use of Facebook user data through a third-party app ecosystem.

Why it still matters: The scandal accelerated scrutiny of platform data governance, consent, third-party access, and privacy accountability.

✣March 19, 2019 — Norsk Hydro ransomware attack

Norsk Hydro suffered a ransomware attack that disrupted global operations and forced substantial manual processing.

Why it still matters: Its response became a widely cited example of transparent crisis communication and resilience.

⊙March 20, 2013 — DarkSeoul attacks

Cyberattacks disrupted major South Korean banks and broadcasters, wiping systems and affecting operations.

Why it still matters: The incident showed how destructive malware can be used for national-level disruption.

⌘March 22, 2022 — Okta / LAPSUS$ incident disclosed

Okta disclosed details around a third-party support engineer compromise after LAPSUS$ published screenshots suggesting access.

Why it still matters: The incident highlighted identity-provider concentration and privileged third-party support risk.

⌘March 23, 2011 — Comodo certificate compromise

A certificate-authority reseller account was compromised and used to issue fraudulent certificates for major online services.

Why it still matters: Web trust depends on the operational security of certificate-issuance infrastructure, not cryptography alone.

✣March 26, 1999 — Melissa

Melissa spread through infected Word documents and Outlook address books, disrupting enterprise mail systems.

Why it still matters: Attackers still win by abusing trust, familiar file formats, and legitimate communication channels.

↗March 29, 2023 — 3CX supply-chain compromise

A trojanized 3CX desktop application was used in a supply-chain attack affecting downstream customers.

Why it still matters: Trusted signed software can become an attack-delivery channel when development or build environments are compromised.

↗March 29, 2024 — XZ Utils backdoor

A sophisticated backdoor was discovered in XZ Utils 5.6.0 and 5.6.1 after malicious code entered upstream release tarballs.

Why it still matters: Patient compromise of an open-source project can create risk far beyond the original repository.

▲March 31, 2022 — Spring4Shell

A critical Spring Framework vulnerability could enable unauthenticated remote code execution under affected configurations.

Why it still matters: It reinforced the challenge of rapidly understanding application-framework exposure across large software estates.

April

8 historical events in the repository

Also this month: ✣ Klez worm surge (2002)
Sun
Mon
Tue
Wed
Thu
Fri
Sat
1
2
3
4
5
6
✣Costa Rica ransomware crisis (2022)
7
▲Heartbleed (2014)
8
9
10
11
12
▲PAN-OS CVE-2024-3400 disclosed (2024)
13
14
▲EternalBlue exploit released publicly (2017)
15
16
17
18
19
20
21
22
23
24
25
26
✣CIH / Chernobyl virus (1999)
◆PlayStation Network breach disclosed (2011)
27
⊙Estonia cyberattacks begin (2007)
28
29
30

April event details

✣April 2002 — Klez worm surge

Klez became a widespread email worm, spoofing sender addresses and distributing infected attachments.

Why it still matters: Sender spoofing and trusted-channel abuse remain basic ingredients of modern social engineering.

✣April 6, 2022 — Costa Rica ransomware crisis

Conti ransomware attacks disrupted multiple Costa Rican government agencies and public services.

Why it still matters: The crisis showed ransomware reaching a level where a national government declared an emergency.

▲April 7, 2014 — Heartbleed

Heartbleed exposed a flaw in OpenSSL heartbeat handling that allowed remote attackers to read portions of process memory.

Why it still matters: It showed how one defect in a ubiquitous security library can create global risk and require key rotation beyond patching.

▲April 12, 2024 — PAN-OS CVE-2024-3400 disclosed

Palo Alto Networks disclosed a critical command-injection vulnerability affecting GlobalProtect on certain PAN-OS configurations.

Why it still matters: Security perimeter devices can become privileged attack paths when Internet-facing components are exploitable.

▲April 14, 2017 — EternalBlue exploit released publicly

The Shadow Brokers released offensive tooling including EternalBlue.

Why it still matters: Public release of weaponized exploit code dramatically shortened the path from vulnerability to widespread criminal use.

✣April 26, 1999 — CIH / Chernobyl virus

CIH overwrote hard-drive data and, on some systems, flash BIOS content when it activated.

Why it still matters: It is an early example of malware designed for destructive impact beyond nuisance or propagation.

◆April 26, 2011 — PlayStation Network breach disclosed

Sony disclosed a major compromise of PlayStation Network and Qriocity user data after taking services offline.

Why it still matters: The incident highlighted large-scale consumer identity exposure and the operational cost of prolonged outages.

⊙April 27, 2007 — Estonia cyberattacks begin

Estonian government, banking, media, and other online services experienced sustained disruptive cyber activity amid political tensions.

Why it still matters: The attacks became a landmark case in national cyber defense, resilience, and geopolitical cyber disruption.

May

12 historical events in the repository

Also this month: ◆ Snowflake customer compromises emerge (2024)
Sun
Mon
Tue
Wed
Thu
Fri
Sat
1
✣Sasser (2004)
2
3
4
✣ILOVEYOU / Love Letter worm (2000)
5
6
7
✣Baltimore ransomware attack (2019)
▥Colonial Pipeline ransomware (2021)
8
9
10
11
12
✣WannaCry (2017)
13
14
▲BlueKeep (2019)
15
16
17
18
19
20
21
22
23
24
25
§GDPR becomes applicable (2018)
26
27
28
⊙Flame malware revealed (2012)
29
30
✣JBS ransomware attack (2021)
31
↗MOVEit zero-day disclosed (2023)
◆Live Nation / Ticketmaster cloud incident (2024)

May event details

✣May 1, 2004 — Sasser

Sasser exploited the Windows LSASS vulnerability and could propagate without a user opening an attachment.

Why it still matters: It reinforced the risk of rapid exploitation following vulnerability disclosure.

◆May 2024 — Snowflake customer compromises emerge

A campaign involving stolen customer credentials affected multiple organizations using Snowflake-hosted data environments.

Why it still matters: Shared cloud platforms amplify the importance of MFA, credential hygiene, and identity logging.

✣May 4, 2000 — ILOVEYOU / Love Letter worm

The Love Letter worm spread through a malicious Visual Basic Script attachment and automated forwarding.

Why it still matters: It combined human psychology with automated propagation, a pattern still visible in modern phishing and malware delivery.

✣May 7, 2019 — Baltimore ransomware attack

Baltimore city systems were disrupted by ransomware, affecting email, property transactions, billing, and municipal services.

Why it still matters: Ransomware can become a public-service continuity problem, not merely an IT outage.

▥May 7, 2021 — Colonial Pipeline ransomware

Colonial Pipeline experienced a network disruption that led to shutdown of pipeline operations; the FBI later confirmed DarkSide ransomware.

Why it still matters: A business-system compromise can create physical-world consequences when operations are shut down for safety or containment.

✣May 12, 2017 — WannaCry

WannaCry spread globally by exploiting an SMB vulnerability Microsoft had patched two months earlier.

Why it still matters: It remains a defining example of the cost of delayed patching, unsupported systems, and flat networks.

▲May 14, 2019 — BlueKeep

Microsoft released fixes for a pre-authentication remote-code-execution vulnerability in Remote Desktop Services and warned it was wormable.

Why it still matters: BlueKeep reinforced the danger of exposed remote administration and end-of-life systems.

§May 25, 2018 — GDPR becomes applicable

The EU General Data Protection Regulation became applicable across member states.

Why it still matters: GDPR materially changed the global privacy landscape and made data governance, security, and privacy inseparable executive concerns.

⊙May 28, 2012 — Flame malware revealed

Researchers disclosed Flame, a sophisticated espionage platform used primarily in the Middle East.

Why it still matters: Flame illustrated the growing complexity and modularity of state-aligned cyber espionage tooling.

✣May 30, 2021 — JBS ransomware attack

JBS experienced a ransomware attack that disrupted meat-processing operations in multiple countries.

Why it still matters: Ransomware against concentrated suppliers can create broader economic and supply-chain risk.

↗May 31, 2023 — MOVEit zero-day disclosed

Progress Software released patches for a critical MOVEit Transfer vulnerability after signs of active exploitation.

Why it still matters: One widely used file-transfer product created cascading third-party data exposure across many organizations.

◆May 31, 2024 — Live Nation / Ticketmaster cloud incident

Live Nation disclosed unauthorized activity in a third-party cloud database environment containing company data including Ticketmaster information.

Why it still matters: The incident highlighted third-party cloud concentration and the use of stolen credentials against SaaS and data platforms.

June

8 historical events in the repository

Also this month: § UK Computer Misuse Act (1990)
Sun
Mon
Tue
Wed
Thu
Fri
Sat
1
2
3
4
◆OPM breach announced (2015)
5
6
◆LinkedIn password breach (2012)
7
8
9
10
11
12
13
14
⊙DNC intrusion disclosed (2016)
15
16
17
▥Stuxnet first identified (2010)
18
19
20
21
22
23
24
25
26
↗Polyfill.io compromise (2024)
27
↗NotPetya (2017)
28
§CCPA signed (2018)
29
30

June event details

§June 1990 — UK Computer Misuse Act

The United Kingdom enacted the Computer Misuse Act, creating criminal offenses for unauthorized access and related computer misuse.

Why it still matters: It became a foundational cybercrime statute and still shapes debates over authorization and security research.

◆June 4, 2015 — OPM breach announced

The U.S. Office of Personnel Management disclosed a major incident affecting federal personnel and background-investigation data.

Why it still matters: The breach demonstrated the intelligence value of aggregated identity and personnel information.

◆June 6, 2012 — LinkedIn password breach

Millions of hashed LinkedIn passwords were posted online following a breach.

Why it still matters: The incident reinforced the importance of strong password hashing, unique credentials, and resistance to credential reuse.

⊙June 14, 2016 — DNC intrusion disclosed

The Democratic National Committee disclosed a network compromise attributed by investigators to Russian intelligence-linked groups.

Why it still matters: The incident became a landmark example of cyber-enabled information operations intersecting with political processes.

▥June 17, 2010 — Stuxnet first identified

Security researchers identified malware later shown to target specific industrial-control environments.

Why it still matters: Its discovery marked a turning point in awareness of cyber weapons designed to manipulate physical processes.

↗June 26, 2024 — Polyfill.io compromise

Cloudflare reported that the popular polyfill.io JavaScript service could no longer be trusted after malicious code injection.

Why it still matters: Externally hosted client-side dependencies can silently become supply-chain channels into huge numbers of websites.

↗June 27, 2017 — NotPetya

NotPetya spread from compromised Ukrainian software into organizations around the world and functioned primarily as destructive malware.

Why it still matters: It remains a textbook example of a targeted supply-chain compromise creating enormous unintended blast radius.

§June 28, 2018 — CCPA signed

California enacted the Consumer Privacy Act, creating new rights around access, deletion, disclosure, and sale of personal information.

Why it still matters: CCPA helped establish a U.S. state-level privacy model that influenced subsequent legislation.

July

15 historical events in the repository

Also this month: ★ First DEF CON (1993)
Sun
Mon
Tue
Wed
Thu
Fri
Sat
1
▲PrintNightmare (2021)
▲regreSSHion (2024)
2
↗Kaseya VSA ransomware attack (2021)
3
4
⊙U.S. and South Korea DDoS attacks (2009)
5
6
7
8
▲Kaminsky DNS flaw disclosed (2008)
◆Hacking Team breach (2015)
9
10
11
12
13
14
15
⌘Twitter account takeover (2020)
16
17
18
19
✣Code Red (2001)
◎CrowdStrike Channel File 291 outage (2024)
20
◆Ashley Madison breach disclosed (2015)
◆SingHealth breach disclosed (2018)
21
22
23
✣Garmin ransomware outage (2020)
24
25
26
§SEC cybersecurity disclosure rules (2023)
27
28
29
◆Capital One breach announced (2019)
30
31

July event details

★July 1993 — First DEF CON

The first DEF CON brought hackers, researchers, and security practitioners together in Las Vegas.

Why it still matters: DEF CON became one of the most influential forums for practical security research and hacker culture.

▲July 1, 2021 — PrintNightmare

Critical Windows Print Spooler vulnerabilities and public exploit code drew widespread attention.

Why it still matters: Legacy services can create high-impact enterprise attack paths, and disclosure confusion can complicate remediation.

▲July 1, 2024 — regreSSHion

Qualys disclosed an unauthenticated remote-code-execution vulnerability in OpenSSH server on affected glibc-based Linux systems.

Why it still matters: Fixed vulnerabilities can return through code changes; regression testing matters even for mature infrastructure software.

↗July 2, 2021 — Kaseya VSA ransomware attack

A ransomware campaign exploited Kaseya VSA and affected managed service providers and downstream customers.

Why it still matters: Management platforms offer attackers enormous leverage because one compromise can cascade into many customers.

⊙July 4, 2009 — U.S. and South Korea DDoS attacks

Government, financial, and media websites in the United States and South Korea were targeted by coordinated denial-of-service attacks.

Why it still matters: The campaign reinforced the use of botnets for politically significant disruption and the difficulty of attribution.

▲July 8, 2008 — Kaminsky DNS flaw disclosed

Dan Kaminsky disclosed a fundamental DNS cache-poisoning weakness after a coordinated multi-vendor patch effort.

Why it still matters: The episode showed the systemic risk of flaws in core Internet infrastructure and the value of coordinated disclosure.

◆July 8, 2015 — Hacking Team breach

Hacking Team’s internal data and source code were leaked following a compromise.

Why it still matters: The breach exposed the commercial offensive-security ecosystem and fueled debate over zero-day markets and surveillance technology.

⌘July 15, 2020 — Twitter account takeover

Attackers compromised internal tools and took over numerous high-profile Twitter accounts to promote a cryptocurrency scam.

Why it still matters: Privileged support workflows can bypass strong user-facing security controls.

✣July 19, 2001 — Code Red

Code Red exploited a vulnerability in Microsoft IIS and infected hundreds of thousands of Internet-facing systems.

Why it still matters: Self-propagating attacks against exposed infrastructure can move faster than human remediation processes.

◎July 19, 2024 — CrowdStrike Channel File 291 outage

A CrowdStrike content configuration update triggered Windows system crashes at global scale; CrowdStrike said it was not a cyberattack.

Why it still matters: The outage demonstrated concentration risk in security tooling and the importance of staged deployment, rollback, validation, and resilience.

◆July 20, 2015 — Ashley Madison breach disclosed

Attackers disclosed a compromise of Ashley Madison and later released stolen user data.

Why it still matters: The incident highlighted the personal, legal, and reputational consequences of breaches involving highly sensitive behavioral data.

◆July 20, 2018 — SingHealth breach disclosed

Singapore disclosed theft of personal data belonging to about 1.5 million SingHealth patients.

Why it still matters: Healthcare data has long-term intelligence and identity-abuse value, not merely immediate financial value.

✣July 23, 2020 — Garmin ransomware outage

Garmin experienced a major outage affecting online services, support, and connected-device synchronization following ransomware.

Why it still matters: Ransomware can disrupt both enterprise operations and customer-facing connected services.

§July 26, 2023 — SEC cybersecurity disclosure rules

The SEC adopted rules requiring public companies to disclose material cyber incidents and annual information about risk management and governance.

Why it still matters: Cybersecurity materiality and governance became explicit securities-law concerns for public companies.

◆July 29, 2019 — Capital One breach announced

Capital One disclosed unauthorized access to personal information associated with credit-card applications and customers.

Why it still matters: The breach became a cloud-security case study in configuration, identity, metadata services, and least privilege.

August

9 historical events in the repository

Sun
Mon
Tue
Wed
Thu
Fri
Sat
1
§EU AI Act enters into force (2024)
2
3
✣Back Orifice released (1998)
4
5
6
7
8
9
10
11
✣Blaster worm (2003)
12
13
⊙Shadow Brokers leaks begin (2016)
14
✣Zotob worm (2005)
15
▥Shamoon attacks Saudi Aramco (2012)
16
17
18
✣Sobig.F (2003)
19
20
21
22
23
24
25
⌘LastPass development-environment breach (2022)
26
27
28
29
⌘DigiNotar fraudulent certificates exposed (2011)
30
31

August event details

§August 1, 2024 — EU AI Act enters into force

The European Union’s AI Act entered into force, establishing a risk-based legal framework for artificial intelligence systems.

Why it still matters: AI governance became a formal compliance discipline increasingly intersecting with cybersecurity, privacy, and digital trust.

✣August 3, 1998 — Back Orifice released

Cult of the Dead Cow released Back Orifice, a remote-administration tool that could covertly control Windows systems.

Why it still matters: It popularized the concept of remote-access trojans and abuse of legitimate administration functions.

✣August 11, 2003 — Blaster worm

Blaster exploited a previously patched Windows RPC vulnerability and scanned continuously for additional vulnerable hosts.

Why it still matters: It illustrates the persistent gap between patch availability and actual remediation.

⊙August 13, 2016 — Shadow Brokers leaks begin

The Shadow Brokers published tools and exploits allegedly associated with the Equation Group.

Why it still matters: Leakage of high-end offensive tooling can rapidly convert state-developed capabilities into broad criminal attack risk.

✣August 14, 2005 — Zotob worm

Zotob exploited a recently disclosed Windows Plug and Play vulnerability and disrupted corporate and media networks.

Why it still matters: It showed how quickly exploit code can follow a patch and why emergency vulnerability management matters.

▥August 15, 2012 — Shamoon attacks Saudi Aramco

Shamoon was used in a destructive attack that wiped large numbers of Saudi Aramco workstations.

Why it still matters: The attack demonstrated the business impact of destructive malware and the importance of segmentation and recovery.

✣August 18, 2003 — Sobig.F

Sobig.F spread through email at enormous scale and generated significant mail disruption.

Why it still matters: Mass-mailing malware showed how compromised endpoints could become infrastructure for large-scale abuse.

⌘August 25, 2022 — LastPass development-environment breach

LastPass disclosed unauthorized access to portions of its development environment through a compromised developer account.

Why it still matters: Technical information and developer access can become building blocks for follow-on compromise.

⌘August 29, 2011 — DigiNotar fraudulent certificates exposed

Fraudulent certificates issued after compromise of DigiNotar were discovered, ultimately destroying trust in the certificate authority.

Why it still matters: Compromise of one PKI trust anchor can create ecosystem-wide consequences.

September

12 historical events in the repository

Also this month: ★ CVE initiative launched (1999)  •  ◆ Caesars Entertainment cyber incident (2023)  •  ⊙ Salt Typhoon telecom intrusions become public (2024)
Sun
Mon
Tue
Wed
Thu
Fri
Sat
1
2
3
4
5
6
7
◆Equifax breach announced (2017)
8
◆Home Depot breach disclosed (2014)
9
10
▥Düsseldorf hospital ransomware incident (2020)
11
12
◆MGM Resorts cyber incident (2023)
13
14
15
⌘Uber intrusion (2022)
16
17
18
✣Nimda (2001)
19
20
21
22
◆Optus breach (2022)
23
24
▲Shellshock (2014)
25
26
27
28
29
▥ICS-CERT Stuxnet advisory (2010)
30

September event details

★September 1999 — CVE initiative launched

MITRE launched Common Vulnerabilities and Exposures to give publicly known vulnerabilities standardized identifiers.

Why it still matters: CVE created a shared language for vulnerability management across vendors, scanners, advisories, and defenders.

◆September 2023 — Caesars Entertainment cyber incident

Caesars disclosed a cyber incident involving theft of loyalty-program customer data and payment to attackers.

Why it still matters: The event reinforced the value of identity data and the role of social engineering in hospitality attacks.

⊙September 2024 — Salt Typhoon telecom intrusions become public

Reports described a China-linked campaign compromising major telecommunications providers and sensitive communications infrastructure.

Why it still matters: Telecom infrastructure is strategic because compromise can provide access to communications, metadata, and intelligence collection.

◆September 7, 2017 — Equifax breach announced

Equifax disclosed a major incident involving highly sensitive consumer identity data.

Why it still matters: It became a defining case for vulnerability management, data concentration, executive accountability, and identity risk.

◆September 8, 2014 — Home Depot breach disclosed

Home Depot disclosed a payment-card breach involving malware on point-of-sale systems.

Why it still matters: Retail breaches reinforced the need for segmentation, payment-environment hardening, and third-party access controls.

▥September 10, 2020 — Düsseldorf hospital ransomware incident

A ransomware incident disrupted systems at a German hospital and was associated with diversion of an emergency patient.

Why it still matters: Cyber incidents in healthcare can create real-world safety consequences.

◆September 12, 2023 — MGM Resorts cyber incident

MGM Resorts disclosed a cybersecurity issue affecting U.S. systems and significant property operations.

Why it still matters: The event showed how identity compromise and containment can rapidly become visible business-operations problems.

⌘September 15, 2022 — Uber intrusion

Uber disclosed a security incident after an attacker gained broad internal access using social engineering and compromised credentials.

Why it still matters: The incident reinforced the importance of phishing-resistant authentication and privileged-access segmentation.

✣September 18, 2001 — Nimda

Nimda spread through email, network shares, compromised websites, vulnerable IIS servers, and earlier backdoors.

Why it still matters: It demonstrated the danger of combining multiple propagation vectors into one campaign.

◆September 22, 2022 — Optus breach

Australian telecom provider Optus disclosed a major breach involving customer identity information.

Why it still matters: Telecommunications providers are high-value targets because they combine identity, account, device, and communications data.

▲September 24, 2014 — Shellshock

Shellshock allowed arbitrary command execution through crafted environment variables processed by GNU Bash.

Why it still matters: It demonstrated the systemic risk created when foundational components are embedded across enormous software estates.

▥September 29, 2010 — ICS-CERT Stuxnet advisory

ICS-CERT documented Stuxnet targeting Siemens industrial-control software and using multiple advanced propagation techniques.

Why it still matters: Stuxnet permanently changed the conversation around cyber-physical risk.

October

11 historical events in the repository

Sun
Mon
Tue
Wed
Thu
Fri
Sat
1
2
◆JPMorgan Chase breach disclosed (2014)
3
◆Adobe breach disclosed (2013)
4
5
6
7
8
9
10
▲Citrix Bleed (2023)
11
12
13
◆Medibank cyber incident (2022)
14
▲POODLE disclosed (2014)
15
16
▲KRACK disclosed (2017)
17
§NIS2 transposition deadline (2024)
18
19
20
⌘Okta support-system breach (2023)
21
◎Mirai / Dyn DDoS attack (2016)
22
23
▲MS08-067 emergency patch (2008)
24
25
26
27
28
29
30
§SEC charges SolarWinds and CISO (2023)
31

October event details

◆October 2, 2014 — JPMorgan Chase breach disclosed

JPMorgan Chase disclosed a major intrusion affecting contact information associated with tens of millions of households and small businesses.

Why it still matters: The incident underscored the scale and attractiveness of identity data held by financial institutions.

◆October 3, 2013 — Adobe breach disclosed

Adobe disclosed an intrusion involving customer information and source code.

Why it still matters: The breach illustrated the value attackers place on both identity data and proprietary software source code.

▲October 10, 2023 — Citrix Bleed

Citrix released updates for a NetScaler vulnerability later associated with session-token theft and session hijacking.

Why it still matters: Patching alone may not terminate attacker access obtained before remediation; session invalidation can also be required.

◆October 13, 2022 — Medibank cyber incident

Australian health insurer Medibank disclosed an incident that later involved theft and publication of highly sensitive customer data.

Why it still matters: Health and claims data can create extreme privacy harm when stolen and used for extortion.

▲October 14, 2014 — POODLE disclosed

Researchers disclosed a weakness in SSL 3.0 that could allow recovery of plaintext from encrypted connections.

Why it still matters: Legacy compatibility can preserve attack paths long after stronger replacements exist.

▲October 16, 2017 — KRACK disclosed

Researchers disclosed key reinstallation attacks against WPA2.

Why it still matters: Even mature, ubiquitous security protocols can fail through subtle state-machine and implementation flaws.

§October 17, 2024 — NIS2 transposition deadline

EU member states reached the deadline for transposing the NIS2 Directive into national law.

Why it still matters: NIS2 raised expectations for governance, supply-chain security, incident reporting, and executive accountability.

⌘October 20, 2023 — Okta support-system breach

Okta disclosed unauthorized access to its customer support case-management system using a stolen credential.

Why it still matters: Identity providers sit at a uniquely sensitive trust boundary, including supporting systems and uploaded troubleshooting artifacts.

◎October 21, 2016 — Mirai / Dyn DDoS attack

A massive DDoS attack targeted DNS provider Dyn using the Mirai botnet, disrupting access to major online services.

Why it still matters: The attack made insecure IoT devices part of the global threat model and highlighted DNS as critical shared infrastructure.

▲October 23, 2008 — MS08-067 emergency patch

Microsoft issued an out-of-band critical update for a remotely exploitable Windows Server service vulnerability.

Why it still matters: The flaw was later exploited by Conficker and remains a classic emergency-patching case.

§October 30, 2023 — SEC charges SolarWinds and CISO

The SEC filed civil charges against SolarWinds and its CISO alleging fraud and internal-control failures related to cybersecurity disclosures.

Why it still matters: The case intensified scrutiny of executive cybersecurity statements, disclosure controls, and personal accountability.

November

10 historical events in the repository

Sun
Mon
Tue
Wed
Thu
Fri
Sat
1
▲OpenSSL CVE-2022-3602 / 3786 (2022)
2
✣Morris Worm (1988)
3
★CISA Known Exploited Vulnerabilities catalog (2021)
4
5
6
7
8
9
10
★Fred Cohen virus demonstration (1983)
11
12
13
14
15
16
★CISA established (2018)
17
★CERT Coordination Center established (1988)
18
19
20
21
✣Conficker discovered (2008)
◆Uber breach disclosed (2017)
22
23
24
◆Sony Pictures destructive attack (2014)
25
26
27
28
29
30
◆Marriott / Starwood breach disclosed (2018)

November event details

▲November 1, 2022 — OpenSSL CVE-2022-3602 / 3786

OpenSSL released fixes for certificate-parsing vulnerabilities that drew broad attention because of the library’s ubiquity.

Why it still matters: The episode reinforced the need for rapid dependency inventory when shared libraries are affected.

✣November 2, 1988 — Morris Worm

The Morris Worm spread rapidly across the early Internet, exploiting multiple weaknesses and affecting thousands of systems.

Why it still matters: It became a foundational Internet security incident and helped drive organized incident-response capability.

★November 3, 2021 — CISA Known Exploited Vulnerabilities catalog

CISA issued BOD 22-01 and operationalized the Known Exploited Vulnerabilities catalog for federal remediation prioritization.

Why it still matters: It helped shift vulnerability management toward exploitation evidence and real-world risk rather than severity scores alone.

★November 10, 1983 — Fred Cohen virus demonstration

Fred Cohen demonstrated self-replicating code during academic security research, helping formalize the modern computer-virus concept.

Why it still matters: It helped turn malicious self-replication into a defined computer-security problem.

★November 16, 2018 — CISA established

The Cybersecurity and Infrastructure Security Agency Act formally established CISA.

Why it still matters: CISA became the central U.S. civilian agency for cyber defense, critical-infrastructure security, and vulnerability coordination.

★November 17, 1988 — CERT Coordination Center established

DARPA funded creation of the CERT Coordination Center at Carnegie Mellon after the Morris Worm.

Why it still matters: Modern incident coordination and vulnerability-response practices trace directly to needs exposed by early Internet-wide incidents.

✣November 21, 2008 — Conficker discovered

Conficker exploited the Windows Server service vulnerability addressed by MS08-067 and added multiple propagation techniques.

Why it still matters: It showed how unpatched systems, weak credentials, removable media, and shares can combine into durable malware spread.

◆November 21, 2017 — Uber breach disclosed

Uber disclosed a 2016 breach involving personal data for millions of riders and drivers and acknowledged paying the attackers.

Why it still matters: The incident became a governance case study in breach disclosure, extortion, and executive accountability.

◆November 24, 2014 — Sony Pictures destructive attack

Sony Pictures suffered a destructive intrusion involving malware, stolen data, and major operational disruption.

Why it still matters: The attack showed how theft, coercion, public disclosure, and destruction can be combined in one campaign.

◆November 30, 2018 — Marriott / Starwood breach disclosed

Marriott announced unauthorized access to the Starwood reservation database involving a large volume of guest data.

Why it still matters: The incident highlighted acquisition due diligence, inherited technology risk, data retention, and long attacker dwell time.

December

9 historical events in the repository

Also this month: ✣ AIDS Trojan / PC Cyborg (1989)  •  § PCI DSS 1.0 (2004)  •  ◆ Heartland Payment Systems breach discovered (2008)
Sun
Mon
Tue
Wed
Thu
Fri
Sat
1
2
3
4
5
6
7
8
◆FireEye breach disclosed (2020)
9
10
▲Log4Shell (2021)
§EU Cyber Resilience Act enters into force (2024)
11
12
13
↗SolarWinds Orion compromise (2020)
14
15
16
17
18
19
◆Target breach announced (2013)
20
21
22
23
▥Ukraine power grid cyberattack (2015)
24
25
26
27
28
29
30
31

December event details

✣December 1989 — AIDS Trojan / PC Cyborg

The AIDS Trojan was distributed on floppy disks, hid directories, encrypted filenames, and demanded payment by postal mail.

Why it still matters: Often cited as the first ransomware, it proves the extortion model predates cryptocurrency by decades.

§December 2004 — PCI DSS 1.0

Major payment-card brands created the first Payment Card Industry Data Security Standard.

Why it still matters: PCI DSS became one of the most influential industry security compliance baselines.

◆December 2008 — Heartland Payment Systems breach discovered

Heartland discovered a major payment-card breach involving malware in transaction-processing systems.

Why it still matters: The case became an important milestone in payment-security accountability and processor risk.

◆December 8, 2020 — FireEye breach disclosed

FireEye disclosed that a sophisticated actor stole proprietary Red Team assessment tools.

Why it still matters: The incident showed the value attackers place on security tooling and the need for rapid public defensive action after compromise.

▲December 10, 2021 — Log4Shell

Log4Shell exposed remote-code-execution risk in widely deployed Apache Log4j versions through JNDI lookup behavior.

Why it still matters: It showed how hidden software dependencies can become enterprise-wide security emergencies.

§December 10, 2024 — EU Cyber Resilience Act enters into force

The Cyber Resilience Act entered into force, establishing cybersecurity requirements for products with digital elements.

Why it still matters: It moves software and hardware security toward lifecycle duty of care, secure-by-design expectations, and manufacturer accountability.

↗December 13, 2020 — SolarWinds Orion compromise

CISA warned of active exploitation involving compromised SolarWinds Orion releases delivered through trusted updates.

Why it still matters: SolarWinds changed how boards and security teams think about software supply chains and privileged management platforms.

◆December 19, 2013 — Target breach announced

Target confirmed unauthorized access to payment-card data affecting tens of millions of accounts.

Why it still matters: The breach became a landmark example of third-party access risk, point-of-sale compromise, and executive accountability.

▥December 23, 2015 — Ukraine power grid cyberattack

A coordinated cyber operation disrupted electricity distribution in Ukraine through enterprise compromise and control-system access.

Why it still matters: It became one of the defining examples of cyber operations causing real-world critical-infrastructure disruption.

YEAR-ROUND REFERENCE

Cyber history, month by month

The XML corpus currently contains 133 records. Each row includes the historical date, event type, substantive context, why it still matters, and available source material.

January (12)
Date Event What happened / why it still matters Sources
January 1986
✣

Brain boot-sector virus
Malware / Worm / Ransomware
Brain spread through infected floppy-disk boot sectors and is widely cited as the first IBM PC-compatible virus to circulate broadly.
Why it still matters: It marks malware’s transition from research curiosity to something that could spread through ordinary computer use.
Background
January 2006
▲

WMF vulnerability crisis
Vulnerability / CVE
A Windows Metafile vulnerability enabled drive-by exploitation through malicious images and triggered an out-of-cycle security update.
Why it still matters: Content-parsing flaws can create code-execution paths through routine web browsing.
Background
January 3, 2018
▲

Meltdown and Spectre
Vulnerability / CVE
Researchers disclosed speculative-execution attacks affecting modern processors.
Why it still matters: The flaws showed that security failures can exist below the operating system and require coordinated hardware and software fixes.
Source
Background
January 7, 2025
◆

PowerSchool breach publicly reported
Breach / Security Incident
PowerSchool disclosed unauthorized access to its student information system environment and data belonging to school districts.
Why it still matters: Concentrated education platforms hold sensitive data on students, parents, and staff and create broad downstream exposure when compromised.
Background
January 10, 2024
▲

Ivanti Connect Secure zero-days
Vulnerability / CVE
Ivanti disclosed critical vulnerabilities affecting Connect Secure and Policy Secure appliances that were being exploited.
Why it still matters: Internet-facing security appliances are prime initial-access targets and require rapid patching plus compromise assessment.
Background
January 11, 2023
✣

Royal Mail ransomware incident
Malware / Worm / Ransomware
A ransomware incident disrupted Royal Mail’s international export services.
Why it still matters: Ransomware against logistics and postal systems can interrupt physical commerce and supply chains.
Background
January 12, 2010
⊙

Operation Aurora disclosed
Nation-State / Espionage
Google disclosed a sophisticated targeted intrusion that stole intellectual property and affected numerous large companies.
Why it still matters: Aurora was a watershed moment in public corporate disclosure of nation-state activity.
Source
Background
January 13, 2022
⊙

WhisperGate destructive malware
Nation-State / Espionage
Microsoft described destructive malware targeting Ukrainian organizations and masquerading as ransomware.
Why it still matters: The campaign foreshadowed use of cyber operations alongside escalating geopolitical conflict.
Source
Background
January 14, 2020
★

Windows 7 end of support
Security Milestone / Foundational Event
Microsoft ended routine support for Windows 7.
Why it still matters: End-of-life operating systems become long-term security liabilities when organizations cannot retire or isolate them.
Source
Background
January 17, 2007
◆

TJX breach disclosed
Breach / Security Incident
TJX disclosed unauthorized access affecting payment-card and customer data across its retail operations.
Why it still matters: The breach became an early large-scale example of wireless security, card-data, and third-party risk failures.
Background
January 25, 2003
✣

SQL Slammer
Malware / Worm / Ransomware
Slammer exploited a previously patched SQL Server flaw and caused a dramatic global traffic spike.
Why it still matters: It remains a classic example of how quickly a worm can weaponize a known vulnerability when patching lags.
Source
Background
January 26, 2004
✣

Mydoom
Malware / Worm / Ransomware
Mydoom spread through email and peer-to-peer networks, opened a backdoor, and launched denial-of-service activity.
Why it still matters: Compromised endpoints quickly became infrastructure for further attacks, a pattern still seen in botnets.
Source
Background
February (14)
Date Event What happened / why it still matters Sources
February 1995
◎

SSL 2.0 era begins
Internet / Infrastructure
Netscape introduced SSL to protect web communications and support secure commercial use of the Internet.
Why it still matters: Encrypted web transport became a basic expectation for online trust, despite weaknesses in early versions.
Background
February 2000
◎

Major Internet DDoS attacks
Internet / Infrastructure
Distributed denial-of-service attacks disrupted major Internet properties including Yahoo, Amazon, CNN, and eBay.
Why it still matters: They demonstrated that even major online services could be overwhelmed through coordinated abuse of compromised systems.
Background
February 2, 2023
✣

ESXiArgs campaign
Malware / Worm / Ransomware
Widespread ransomware exploitation targeted Internet-exposed VMware ESXi systems.
Why it still matters: Exposed virtualization infrastructure creates difficult recovery scenarios when hypervisors themselves are encrypted.
Source
Background
February 4, 2015
◆

Anthem breach disclosed
Breach / Security Incident
Anthem disclosed unauthorized access to a database containing information on current and former members and employees.
Why it still matters: Healthcare identity data has long-lived value and creates exposure that persists well beyond incident containment.
Background
February 4, 2016
◆

Bangladesh Bank cyber heist
Breach / Security Incident
Attackers used compromised systems and fraudulent SWIFT messages in an attempt to steal nearly $1 billion from Bangladesh Bank.
Why it still matters: The heist showed how cyber compromise can manipulate trusted financial messaging and payment processes.
Background
February 12, 2001
✣

Anna Kournikova worm
Malware / Worm / Ransomware
A social-engineering worm disguised as an image of tennis player Anna Kournikova spread widely through email.
Why it still matters: Compelling lures and trusted communication channels remain durable malware-delivery techniques.
Background
February 12, 2014
§

NIST Cybersecurity Framework 1.0
Regulation / Governance / Policy
NIST released the first Framework for Improving Critical Infrastructure Cybersecurity.
Why it still matters: The Framework created a common risk-based language for cybersecurity outcomes and executive communication.
Source
Background
February 16, 2016
✣

Hollywood Presbyterian ransomware payment
Malware / Worm / Ransomware
A hospital paid ransom after ransomware disrupted access to systems and records.
Why it still matters: Healthcare became one of the earliest sectors to show how ransomware could affect service delivery and patient-care operations.
Background
February 19, 2013
⊙

Mandiant APT1 report
Nation-State / Espionage
Mandiant published a detailed report linking a large cyber-espionage campaign to a unit of China’s People’s Liberation Army.
Why it still matters: The report helped normalize evidence-based public attribution of state-sponsored cyber operations.
Background
February 21, 2024
▥

Change Healthcare cyberattack
Critical Infrastructure / ICS
UnitedHealth disclosed a cyberattack affecting Change Healthcare and disrupting claims, payments, pharmacy, and healthcare transactions.
Why it still matters: Concentration in a critical third-party platform can turn one compromise into a sector-wide operational problem.
Source
Background
February 23, 2017
▲

Cloudbleed
Vulnerability / CVE
Cloudflare disclosed a memory-leak bug that could expose sensitive data from customer websites.
Why it still matters: Shared cloud and edge infrastructure bugs can create cross-tenant confidentiality risk.
Source
Background
February 23, 2022
⊙

HermeticWiper attacks
Nation-State / Espionage
Destructive wiper malware was deployed against Ukrainian organizations immediately before Russia’s full-scale invasion.
Why it still matters: The campaign showed how destructive cyber operations can be integrated into broader military conflict.
Background
February 26, 2024
§

NIST Cybersecurity Framework 2.0
Regulation / Governance / Policy
NIST released CSF 2.0, expanding applicability and adding the Govern function.
Why it still matters: It formalized cybersecurity as an enterprise governance responsibility, not merely a technical function.
Source
Background
February 27, 2018
◎

GitHub 1.35 Tbps DDoS
Internet / Infrastructure
GitHub experienced a record-setting DDoS attack amplified through exposed memcached servers.
Why it still matters: Misconfigured Internet infrastructure can be weaponized for enormous amplification attacks.
Source
Background
March (13)
Date Event What happened / why it still matters Sources
March 1, 2017
§

NYDFS Cybersecurity Regulation
Regulation / Governance / Policy
New York’s cybersecurity regulation took effect for covered financial institutions.
Why it still matters: The rule helped normalize executive accountability, risk assessment, incident reporting, and program governance in financial services.
Source
Background
March 2, 2021
⊙

HAFNIUM / Exchange zero-days
Nation-State / Espionage
Microsoft disclosed active exploitation of previously unknown Exchange Server vulnerabilities by a China-based threat actor it called HAFNIUM.
Why it still matters: Internet-facing messaging infrastructure became a direct path into enterprise networks.
Source
Background
March 14, 2017
▲

MS17-010 released
Vulnerability / CVE
Microsoft fixed critical SMBv1 vulnerabilities including the flaw later associated with EternalBlue.
Why it still matters: Organizations had nearly two months to patch before WannaCry weaponized the flaw at global scale.
Source
Background
March 17, 2011
⌘

RSA SecurID breach disclosed
Identity / Authentication / PKI
RSA disclosed an advanced persistent threat and warned that information related to SecurID products had been extracted.
Why it still matters: Security controls with privileged trust relationships are strategic targets in their own right.
Source
Background
March 17, 2018
§

Cambridge Analytica scandal breaks widely
Regulation / Governance / Policy
Reporting revealed large-scale harvesting and political use of Facebook user data through a third-party app ecosystem.
Why it still matters: The scandal accelerated scrutiny of platform data governance, consent, third-party access, and privacy accountability.
Background
March 19, 2019
✣

Norsk Hydro ransomware attack
Malware / Worm / Ransomware
Norsk Hydro suffered a ransomware attack that disrupted global operations and forced substantial manual processing.
Why it still matters: Its response became a widely cited example of transparent crisis communication and resilience.
Background
March 20, 2013
⊙

DarkSeoul attacks
Nation-State / Espionage
Cyberattacks disrupted major South Korean banks and broadcasters, wiping systems and affecting operations.
Why it still matters: The incident showed how destructive malware can be used for national-level disruption.
Background
March 22, 2022
⌘

Okta / LAPSUS$ incident disclosed
Identity / Authentication / PKI
Okta disclosed details around a third-party support engineer compromise after LAPSUS$ published screenshots suggesting access.
Why it still matters: The incident highlighted identity-provider concentration and privileged third-party support risk.
Background
March 23, 2011
⌘

Comodo certificate compromise
Identity / Authentication / PKI
A certificate-authority reseller account was compromised and used to issue fraudulent certificates for major online services.
Why it still matters: Web trust depends on the operational security of certificate-issuance infrastructure, not cryptography alone.
Background
March 26, 1999
✣

Melissa
Malware / Worm / Ransomware
Melissa spread through infected Word documents and Outlook address books, disrupting enterprise mail systems.
Why it still matters: Attackers still win by abusing trust, familiar file formats, and legitimate communication channels.
Source
Background
March 29, 2023
↗

3CX supply-chain compromise
Supply Chain / Third Party
A trojanized 3CX desktop application was used in a supply-chain attack affecting downstream customers.
Why it still matters: Trusted signed software can become an attack-delivery channel when development or build environments are compromised.
Source
Background
March 29, 2024
↗

XZ Utils backdoor
Supply Chain / Third Party
A sophisticated backdoor was discovered in XZ Utils 5.6.0 and 5.6.1 after malicious code entered upstream release tarballs.
Why it still matters: Patient compromise of an open-source project can create risk far beyond the original repository.
Source
Background
March 31, 2022
▲

Spring4Shell
Vulnerability / CVE
A critical Spring Framework vulnerability could enable unauthenticated remote code execution under affected configurations.
Why it still matters: It reinforced the challenge of rapidly understanding application-framework exposure across large software estates.
Source
Background
April (8)
Date Event What happened / why it still matters Sources
April 2002
✣

Klez worm surge
Malware / Worm / Ransomware
Klez became a widespread email worm, spoofing sender addresses and distributing infected attachments.
Why it still matters: Sender spoofing and trusted-channel abuse remain basic ingredients of modern social engineering.
Background
April 6, 2022
✣

Costa Rica ransomware crisis
Malware / Worm / Ransomware
Conti ransomware attacks disrupted multiple Costa Rican government agencies and public services.
Why it still matters: The crisis showed ransomware reaching a level where a national government declared an emergency.
Background
April 7, 2014
▲

Heartbleed
Vulnerability / CVE
Heartbleed exposed a flaw in OpenSSL heartbeat handling that allowed remote attackers to read portions of process memory.
Why it still matters: It showed how one defect in a ubiquitous security library can create global risk and require key rotation beyond patching.
Source
Background
April 12, 2024
▲

PAN-OS CVE-2024-3400 disclosed
Vulnerability / CVE
Palo Alto Networks disclosed a critical command-injection vulnerability affecting GlobalProtect on certain PAN-OS configurations.
Why it still matters: Security perimeter devices can become privileged attack paths when Internet-facing components are exploitable.
Source
Background
April 14, 2017
▲

EternalBlue exploit released publicly
Vulnerability / CVE
The Shadow Brokers released offensive tooling including EternalBlue.
Why it still matters: Public release of weaponized exploit code dramatically shortened the path from vulnerability to widespread criminal use.
Background
April 26, 1999
✣

CIH / Chernobyl virus
Malware / Worm / Ransomware
CIH overwrote hard-drive data and, on some systems, flash BIOS content when it activated.
Why it still matters: It is an early example of malware designed for destructive impact beyond nuisance or propagation.
Source
Background
April 26, 2011
◆

PlayStation Network breach disclosed
Breach / Security Incident
Sony disclosed a major compromise of PlayStation Network and Qriocity user data after taking services offline.
Why it still matters: The incident highlighted large-scale consumer identity exposure and the operational cost of prolonged outages.
Background
April 27, 2007
⊙

Estonia cyberattacks begin
Nation-State / Espionage
Estonian government, banking, media, and other online services experienced sustained disruptive cyber activity amid political tensions.
Why it still matters: The attacks became a landmark case in national cyber defense, resilience, and geopolitical cyber disruption.
Background
May (12)
Date Event What happened / why it still matters Sources
May 1, 2004
✣

Sasser
Malware / Worm / Ransomware
Sasser exploited the Windows LSASS vulnerability and could propagate without a user opening an attachment.
Why it still matters: It reinforced the risk of rapid exploitation following vulnerability disclosure.
Source
Background
May 2024
◆

Snowflake customer compromises emerge
Breach / Security Incident
A campaign involving stolen customer credentials affected multiple organizations using Snowflake-hosted data environments.
Why it still matters: Shared cloud platforms amplify the importance of MFA, credential hygiene, and identity logging.
Background
May 4, 2000
✣

ILOVEYOU / Love Letter worm
Malware / Worm / Ransomware
The Love Letter worm spread through a malicious Visual Basic Script attachment and automated forwarding.
Why it still matters: It combined human psychology with automated propagation, a pattern still visible in modern phishing and malware delivery.
Source
Background
May 7, 2019
✣

Baltimore ransomware attack
Malware / Worm / Ransomware
Baltimore city systems were disrupted by ransomware, affecting email, property transactions, billing, and municipal services.
Why it still matters: Ransomware can become a public-service continuity problem, not merely an IT outage.
Background
May 7, 2021
▥

Colonial Pipeline ransomware
Critical Infrastructure / ICS
Colonial Pipeline experienced a network disruption that led to shutdown of pipeline operations; the FBI later confirmed DarkSide ransomware.
Why it still matters: A business-system compromise can create physical-world consequences when operations are shut down for safety or containment.
Source
Background
May 12, 2017
✣

WannaCry
Malware / Worm / Ransomware
WannaCry spread globally by exploiting an SMB vulnerability Microsoft had patched two months earlier.
Why it still matters: It remains a defining example of the cost of delayed patching, unsupported systems, and flat networks.
Source
Background
May 14, 2019
▲

BlueKeep
Vulnerability / CVE
Microsoft released fixes for a pre-authentication remote-code-execution vulnerability in Remote Desktop Services and warned it was wormable.
Why it still matters: BlueKeep reinforced the danger of exposed remote administration and end-of-life systems.
Source
Background
May 25, 2018
§

GDPR becomes applicable
Regulation / Governance / Policy
The EU General Data Protection Regulation became applicable across member states.
Why it still matters: GDPR materially changed the global privacy landscape and made data governance, security, and privacy inseparable executive concerns.
Source
Background
May 28, 2012
⊙

Flame malware revealed
Nation-State / Espionage
Researchers disclosed Flame, a sophisticated espionage platform used primarily in the Middle East.
Why it still matters: Flame illustrated the growing complexity and modularity of state-aligned cyber espionage tooling.
Background
May 30, 2021
✣

JBS ransomware attack
Malware / Worm / Ransomware
JBS experienced a ransomware attack that disrupted meat-processing operations in multiple countries.
Why it still matters: Ransomware against concentrated suppliers can create broader economic and supply-chain risk.
Background
May 31, 2023
↗

MOVEit zero-day disclosed
Supply Chain / Third Party
Progress Software released patches for a critical MOVEit Transfer vulnerability after signs of active exploitation.
Why it still matters: One widely used file-transfer product created cascading third-party data exposure across many organizations.
Source
Background
May 31, 2024
◆

Live Nation / Ticketmaster cloud incident
Breach / Security Incident
Live Nation disclosed unauthorized activity in a third-party cloud database environment containing company data including Ticketmaster information.
Why it still matters: The incident highlighted third-party cloud concentration and the use of stolen credentials against SaaS and data platforms.
Source
Background
June (8)
Date Event What happened / why it still matters Sources
June 1990
§

UK Computer Misuse Act
Regulation / Governance / Policy
The United Kingdom enacted the Computer Misuse Act, creating criminal offenses for unauthorized access and related computer misuse.
Why it still matters: It became a foundational cybercrime statute and still shapes debates over authorization and security research.
Background
June 4, 2015
◆

OPM breach announced
Breach / Security Incident
The U.S. Office of Personnel Management disclosed a major incident affecting federal personnel and background-investigation data.
Why it still matters: The breach demonstrated the intelligence value of aggregated identity and personnel information.
Source
Background
June 6, 2012
◆

LinkedIn password breach
Breach / Security Incident
Millions of hashed LinkedIn passwords were posted online following a breach.
Why it still matters: The incident reinforced the importance of strong password hashing, unique credentials, and resistance to credential reuse.
Background
June 14, 2016
⊙

DNC intrusion disclosed
Nation-State / Espionage
The Democratic National Committee disclosed a network compromise attributed by investigators to Russian intelligence-linked groups.
Why it still matters: The incident became a landmark example of cyber-enabled information operations intersecting with political processes.
Background
June 17, 2010
▥

Stuxnet first identified
Critical Infrastructure / ICS
Security researchers identified malware later shown to target specific industrial-control environments.
Why it still matters: Its discovery marked a turning point in awareness of cyber weapons designed to manipulate physical processes.
Background
June 26, 2024
↗

Polyfill.io compromise
Supply Chain / Third Party
Cloudflare reported that the popular polyfill.io JavaScript service could no longer be trusted after malicious code injection.
Why it still matters: Externally hosted client-side dependencies can silently become supply-chain channels into huge numbers of websites.
Source
Background
June 27, 2017
↗

NotPetya
Supply Chain / Third Party
NotPetya spread from compromised Ukrainian software into organizations around the world and functioned primarily as destructive malware.
Why it still matters: It remains a textbook example of a targeted supply-chain compromise creating enormous unintended blast radius.
Source
Background
June 28, 2018
§

CCPA signed
Regulation / Governance / Policy
California enacted the Consumer Privacy Act, creating new rights around access, deletion, disclosure, and sale of personal information.
Why it still matters: CCPA helped establish a U.S. state-level privacy model that influenced subsequent legislation.
Source
Background
July (15)
Date Event What happened / why it still matters Sources
July 1993
★

First DEF CON
Security Milestone / Foundational Event
The first DEF CON brought hackers, researchers, and security practitioners together in Las Vegas.
Why it still matters: DEF CON became one of the most influential forums for practical security research and hacker culture.
Background
July 1, 2021
▲

PrintNightmare
Vulnerability / CVE
Critical Windows Print Spooler vulnerabilities and public exploit code drew widespread attention.
Why it still matters: Legacy services can create high-impact enterprise attack paths, and disclosure confusion can complicate remediation.
Background
July 1, 2024
▲

regreSSHion
Vulnerability / CVE
Qualys disclosed an unauthenticated remote-code-execution vulnerability in OpenSSH server on affected glibc-based Linux systems.
Why it still matters: Fixed vulnerabilities can return through code changes; regression testing matters even for mature infrastructure software.
Source
Background
July 2, 2021
↗

Kaseya VSA ransomware attack
Supply Chain / Third Party
A ransomware campaign exploited Kaseya VSA and affected managed service providers and downstream customers.
Why it still matters: Management platforms offer attackers enormous leverage because one compromise can cascade into many customers.
Source
Background
July 4, 2009
⊙

U.S. and South Korea DDoS attacks
Nation-State / Espionage
Government, financial, and media websites in the United States and South Korea were targeted by coordinated denial-of-service attacks.
Why it still matters: The campaign reinforced the use of botnets for politically significant disruption and the difficulty of attribution.
Background
July 8, 2008
▲

Kaminsky DNS flaw disclosed
Vulnerability / CVE
Dan Kaminsky disclosed a fundamental DNS cache-poisoning weakness after a coordinated multi-vendor patch effort.
Why it still matters: The episode showed the systemic risk of flaws in core Internet infrastructure and the value of coordinated disclosure.
Background
July 8, 2015
◆

Hacking Team breach
Breach / Security Incident
Hacking Team’s internal data and source code were leaked following a compromise.
Why it still matters: The breach exposed the commercial offensive-security ecosystem and fueled debate over zero-day markets and surveillance technology.
Background
July 15, 2020
⌘

Twitter account takeover
Identity / Authentication / PKI
Attackers compromised internal tools and took over numerous high-profile Twitter accounts to promote a cryptocurrency scam.
Why it still matters: Privileged support workflows can bypass strong user-facing security controls.
Background
July 19, 2001
✣

Code Red
Malware / Worm / Ransomware
Code Red exploited a vulnerability in Microsoft IIS and infected hundreds of thousands of Internet-facing systems.
Why it still matters: Self-propagating attacks against exposed infrastructure can move faster than human remediation processes.
Source
Background
July 19, 2024
◎

CrowdStrike Channel File 291 outage
Internet / Infrastructure
A CrowdStrike content configuration update triggered Windows system crashes at global scale; CrowdStrike said it was not a cyberattack.
Why it still matters: The outage demonstrated concentration risk in security tooling and the importance of staged deployment, rollback, validation, and resilience.
Source
Background
July 20, 2015
◆

Ashley Madison breach disclosed
Breach / Security Incident
Attackers disclosed a compromise of Ashley Madison and later released stolen user data.
Why it still matters: The incident highlighted the personal, legal, and reputational consequences of breaches involving highly sensitive behavioral data.
Background
July 20, 2018
◆

SingHealth breach disclosed
Breach / Security Incident
Singapore disclosed theft of personal data belonging to about 1.5 million SingHealth patients.
Why it still matters: Healthcare data has long-term intelligence and identity-abuse value, not merely immediate financial value.
Source
Background
July 23, 2020
✣

Garmin ransomware outage
Malware / Worm / Ransomware
Garmin experienced a major outage affecting online services, support, and connected-device synchronization following ransomware.
Why it still matters: Ransomware can disrupt both enterprise operations and customer-facing connected services.
Background
July 26, 2023
§

SEC cybersecurity disclosure rules
Regulation / Governance / Policy
The SEC adopted rules requiring public companies to disclose material cyber incidents and annual information about risk management and governance.
Why it still matters: Cybersecurity materiality and governance became explicit securities-law concerns for public companies.
Source
Background
July 29, 2019
◆

Capital One breach announced
Breach / Security Incident
Capital One disclosed unauthorized access to personal information associated with credit-card applications and customers.
Why it still matters: The breach became a cloud-security case study in configuration, identity, metadata services, and least privilege.
Source
Background
August (9)
Date Event What happened / why it still matters Sources
August 1, 2024
§

EU AI Act enters into force
Regulation / Governance / Policy
The European Union’s AI Act entered into force, establishing a risk-based legal framework for artificial intelligence systems.
Why it still matters: AI governance became a formal compliance discipline increasingly intersecting with cybersecurity, privacy, and digital trust.
Source
Background
August 3, 1998
✣

Back Orifice released
Malware / Worm / Ransomware
Cult of the Dead Cow released Back Orifice, a remote-administration tool that could covertly control Windows systems.
Why it still matters: It popularized the concept of remote-access trojans and abuse of legitimate administration functions.
Background
August 11, 2003
✣

Blaster worm
Malware / Worm / Ransomware
Blaster exploited a previously patched Windows RPC vulnerability and scanned continuously for additional vulnerable hosts.
Why it still matters: It illustrates the persistent gap between patch availability and actual remediation.
Source
Background
August 13, 2016
⊙

Shadow Brokers leaks begin
Nation-State / Espionage
The Shadow Brokers published tools and exploits allegedly associated with the Equation Group.
Why it still matters: Leakage of high-end offensive tooling can rapidly convert state-developed capabilities into broad criminal attack risk.
Background
August 14, 2005
✣

Zotob worm
Malware / Worm / Ransomware
Zotob exploited a recently disclosed Windows Plug and Play vulnerability and disrupted corporate and media networks.
Why it still matters: It showed how quickly exploit code can follow a patch and why emergency vulnerability management matters.
Background
August 15, 2012
▥

Shamoon attacks Saudi Aramco
Critical Infrastructure / ICS
Shamoon was used in a destructive attack that wiped large numbers of Saudi Aramco workstations.
Why it still matters: The attack demonstrated the business impact of destructive malware and the importance of segmentation and recovery.
Background
August 18, 2003
✣

Sobig.F
Malware / Worm / Ransomware
Sobig.F spread through email at enormous scale and generated significant mail disruption.
Why it still matters: Mass-mailing malware showed how compromised endpoints could become infrastructure for large-scale abuse.
Background
August 25, 2022
⌘

LastPass development-environment breach
Identity / Authentication / PKI
LastPass disclosed unauthorized access to portions of its development environment through a compromised developer account.
Why it still matters: Technical information and developer access can become building blocks for follow-on compromise.
Source
Background
August 29, 2011
⌘

DigiNotar fraudulent certificates exposed
Identity / Authentication / PKI
Fraudulent certificates issued after compromise of DigiNotar were discovered, ultimately destroying trust in the certificate authority.
Why it still matters: Compromise of one PKI trust anchor can create ecosystem-wide consequences.
Background
September (12)
Date Event What happened / why it still matters Sources
September 1999
★

CVE initiative launched
Security Milestone / Foundational Event
MITRE launched Common Vulnerabilities and Exposures to give publicly known vulnerabilities standardized identifiers.
Why it still matters: CVE created a shared language for vulnerability management across vendors, scanners, advisories, and defenders.
Source
Background
September 2023
◆

Caesars Entertainment cyber incident
Breach / Security Incident
Caesars disclosed a cyber incident involving theft of loyalty-program customer data and payment to attackers.
Why it still matters: The event reinforced the value of identity data and the role of social engineering in hospitality attacks.
Background
September 2024
⊙

Salt Typhoon telecom intrusions become public
Nation-State / Espionage
Reports described a China-linked campaign compromising major telecommunications providers and sensitive communications infrastructure.
Why it still matters: Telecom infrastructure is strategic because compromise can provide access to communications, metadata, and intelligence collection.
Background
September 7, 2017
◆

Equifax breach announced
Breach / Security Incident
Equifax disclosed a major incident involving highly sensitive consumer identity data.
Why it still matters: It became a defining case for vulnerability management, data concentration, executive accountability, and identity risk.
Source
Background
September 8, 2014
◆

Home Depot breach disclosed
Breach / Security Incident
Home Depot disclosed a payment-card breach involving malware on point-of-sale systems.
Why it still matters: Retail breaches reinforced the need for segmentation, payment-environment hardening, and third-party access controls.
Background
September 10, 2020
▥

Düsseldorf hospital ransomware incident
Critical Infrastructure / ICS
A ransomware incident disrupted systems at a German hospital and was associated with diversion of an emergency patient.
Why it still matters: Cyber incidents in healthcare can create real-world safety consequences.
Background
September 12, 2023
◆

MGM Resorts cyber incident
Breach / Security Incident
MGM Resorts disclosed a cybersecurity issue affecting U.S. systems and significant property operations.
Why it still matters: The event showed how identity compromise and containment can rapidly become visible business-operations problems.
Source
Background
September 15, 2022
⌘

Uber intrusion
Identity / Authentication / PKI
Uber disclosed a security incident after an attacker gained broad internal access using social engineering and compromised credentials.
Why it still matters: The incident reinforced the importance of phishing-resistant authentication and privileged-access segmentation.
Background
September 18, 2001
✣

Nimda
Malware / Worm / Ransomware
Nimda spread through email, network shares, compromised websites, vulnerable IIS servers, and earlier backdoors.
Why it still matters: It demonstrated the danger of combining multiple propagation vectors into one campaign.
Source
Background
September 22, 2022
◆

Optus breach
Breach / Security Incident
Australian telecom provider Optus disclosed a major breach involving customer identity information.
Why it still matters: Telecommunications providers are high-value targets because they combine identity, account, device, and communications data.
Background
September 24, 2014
▲

Shellshock
Vulnerability / CVE
Shellshock allowed arbitrary command execution through crafted environment variables processed by GNU Bash.
Why it still matters: It demonstrated the systemic risk created when foundational components are embedded across enormous software estates.
Source
Background
September 29, 2010
▥

ICS-CERT Stuxnet advisory
Critical Infrastructure / ICS
ICS-CERT documented Stuxnet targeting Siemens industrial-control software and using multiple advanced propagation techniques.
Why it still matters: Stuxnet permanently changed the conversation around cyber-physical risk.
Source
Background
October (11)
Date Event What happened / why it still matters Sources
October 2, 2014
◆

JPMorgan Chase breach disclosed
Breach / Security Incident
JPMorgan Chase disclosed a major intrusion affecting contact information associated with tens of millions of households and small businesses.
Why it still matters: The incident underscored the scale and attractiveness of identity data held by financial institutions.
Background
October 3, 2013
◆

Adobe breach disclosed
Breach / Security Incident
Adobe disclosed an intrusion involving customer information and source code.
Why it still matters: The breach illustrated the value attackers place on both identity data and proprietary software source code.
Background
October 10, 2023
▲

Citrix Bleed
Vulnerability / CVE
Citrix released updates for a NetScaler vulnerability later associated with session-token theft and session hijacking.
Why it still matters: Patching alone may not terminate attacker access obtained before remediation; session invalidation can also be required.
Source
Background
October 13, 2022
◆

Medibank cyber incident
Breach / Security Incident
Australian health insurer Medibank disclosed an incident that later involved theft and publication of highly sensitive customer data.
Why it still matters: Health and claims data can create extreme privacy harm when stolen and used for extortion.
Background
October 14, 2014
▲

POODLE disclosed
Vulnerability / CVE
Researchers disclosed a weakness in SSL 3.0 that could allow recovery of plaintext from encrypted connections.
Why it still matters: Legacy compatibility can preserve attack paths long after stronger replacements exist.
Source
Background
October 16, 2017
▲

KRACK disclosed
Vulnerability / CVE
Researchers disclosed key reinstallation attacks against WPA2.
Why it still matters: Even mature, ubiquitous security protocols can fail through subtle state-machine and implementation flaws.
Background
October 17, 2024
§

NIS2 transposition deadline
Regulation / Governance / Policy
EU member states reached the deadline for transposing the NIS2 Directive into national law.
Why it still matters: NIS2 raised expectations for governance, supply-chain security, incident reporting, and executive accountability.
Background
October 20, 2023
⌘

Okta support-system breach
Identity / Authentication / PKI
Okta disclosed unauthorized access to its customer support case-management system using a stolen credential.
Why it still matters: Identity providers sit at a uniquely sensitive trust boundary, including supporting systems and uploaded troubleshooting artifacts.
Source
Background
October 21, 2016
◎

Mirai / Dyn DDoS attack
Internet / Infrastructure
A massive DDoS attack targeted DNS provider Dyn using the Mirai botnet, disrupting access to major online services.
Why it still matters: The attack made insecure IoT devices part of the global threat model and highlighted DNS as critical shared infrastructure.
Background
October 23, 2008
▲

MS08-067 emergency patch
Vulnerability / CVE
Microsoft issued an out-of-band critical update for a remotely exploitable Windows Server service vulnerability.
Why it still matters: The flaw was later exploited by Conficker and remains a classic emergency-patching case.
Source
Background
October 30, 2023
§

SEC charges SolarWinds and CISO
Regulation / Governance / Policy
The SEC filed civil charges against SolarWinds and its CISO alleging fraud and internal-control failures related to cybersecurity disclosures.
Why it still matters: The case intensified scrutiny of executive cybersecurity statements, disclosure controls, and personal accountability.
Source
Background
November (10)
Date Event What happened / why it still matters Sources
November 1, 2022
▲

OpenSSL CVE-2022-3602 / 3786
Vulnerability / CVE
OpenSSL released fixes for certificate-parsing vulnerabilities that drew broad attention because of the library’s ubiquity.
Why it still matters: The episode reinforced the need for rapid dependency inventory when shared libraries are affected.
Source
Background
November 2, 1988
✣

Morris Worm
Malware / Worm / Ransomware
The Morris Worm spread rapidly across the early Internet, exploiting multiple weaknesses and affecting thousands of systems.
Why it still matters: It became a foundational Internet security incident and helped drive organized incident-response capability.
Source
Background
November 3, 2021
★

CISA Known Exploited Vulnerabilities catalog
Security Milestone / Foundational Event
CISA issued BOD 22-01 and operationalized the Known Exploited Vulnerabilities catalog for federal remediation prioritization.
Why it still matters: It helped shift vulnerability management toward exploitation evidence and real-world risk rather than severity scores alone.
Source
Background
November 10, 1983
★

Fred Cohen virus demonstration
Security Milestone / Foundational Event
Fred Cohen demonstrated self-replicating code during academic security research, helping formalize the modern computer-virus concept.
Why it still matters: It helped turn malicious self-replication into a defined computer-security problem.
Background
November 16, 2018
★

CISA established
Security Milestone / Foundational Event
The Cybersecurity and Infrastructure Security Agency Act formally established CISA.
Why it still matters: CISA became the central U.S. civilian agency for cyber defense, critical-infrastructure security, and vulnerability coordination.
Source
Background
November 17, 1988
★

CERT Coordination Center established
Security Milestone / Foundational Event
DARPA funded creation of the CERT Coordination Center at Carnegie Mellon after the Morris Worm.
Why it still matters: Modern incident coordination and vulnerability-response practices trace directly to needs exposed by early Internet-wide incidents.
Source
Background
November 21, 2008
✣

Conficker discovered
Malware / Worm / Ransomware
Conficker exploited the Windows Server service vulnerability addressed by MS08-067 and added multiple propagation techniques.
Why it still matters: It showed how unpatched systems, weak credentials, removable media, and shares can combine into durable malware spread.
Source
Background
November 21, 2017
◆

Uber breach disclosed
Breach / Security Incident
Uber disclosed a 2016 breach involving personal data for millions of riders and drivers and acknowledged paying the attackers.
Why it still matters: The incident became a governance case study in breach disclosure, extortion, and executive accountability.
Background
November 24, 2014
◆

Sony Pictures destructive attack
Breach / Security Incident
Sony Pictures suffered a destructive intrusion involving malware, stolen data, and major operational disruption.
Why it still matters: The attack showed how theft, coercion, public disclosure, and destruction can be combined in one campaign.
Source
Background
November 30, 2018
◆

Marriott / Starwood breach disclosed
Breach / Security Incident
Marriott announced unauthorized access to the Starwood reservation database involving a large volume of guest data.
Why it still matters: The incident highlighted acquisition due diligence, inherited technology risk, data retention, and long attacker dwell time.
Background
December (9)
Date Event What happened / why it still matters Sources
December 1989
✣

AIDS Trojan / PC Cyborg
Malware / Worm / Ransomware
The AIDS Trojan was distributed on floppy disks, hid directories, encrypted filenames, and demanded payment by postal mail.
Why it still matters: Often cited as the first ransomware, it proves the extortion model predates cryptocurrency by decades.
Source
Background
December 2004
§

PCI DSS 1.0
Regulation / Governance / Policy
Major payment-card brands created the first Payment Card Industry Data Security Standard.
Why it still matters: PCI DSS became one of the most influential industry security compliance baselines.
Source
Background
December 2008
◆

Heartland Payment Systems breach discovered
Breach / Security Incident
Heartland discovered a major payment-card breach involving malware in transaction-processing systems.
Why it still matters: The case became an important milestone in payment-security accountability and processor risk.
Background
December 8, 2020
◆

FireEye breach disclosed
Breach / Security Incident
FireEye disclosed that a sophisticated actor stole proprietary Red Team assessment tools.
Why it still matters: The incident showed the value attackers place on security tooling and the need for rapid public defensive action after compromise.
Source
Background
December 10, 2021
▲

Log4Shell
Vulnerability / CVE
Log4Shell exposed remote-code-execution risk in widely deployed Apache Log4j versions through JNDI lookup behavior.
Why it still matters: It showed how hidden software dependencies can become enterprise-wide security emergencies.
Source
Background
December 10, 2024
§

EU Cyber Resilience Act enters into force
Regulation / Governance / Policy
The Cyber Resilience Act entered into force, establishing cybersecurity requirements for products with digital elements.
Why it still matters: It moves software and hardware security toward lifecycle duty of care, secure-by-design expectations, and manufacturer accountability.
Source
Background
December 13, 2020
↗

SolarWinds Orion compromise
Supply Chain / Third Party
CISA warned of active exploitation involving compromised SolarWinds Orion releases delivered through trusted updates.
Why it still matters: SolarWinds changed how boards and security teams think about software supply chains and privileged management platforms.
Source
Background
December 19, 2013
◆

Target breach announced
Breach / Security Incident
Target confirmed unauthorized access to payment-card data affecting tens of millions of accounts.
Why it still matters: The breach became a landmark example of third-party access risk, point-of-sale compromise, and executive accountability.
Source
Background
December 23, 2015
▥

Ukraine power grid cyberattack
Critical Infrastructure / ICS
A coordinated cyber operation disrupted electricity distribution in Ukraine through enterprise compromise and control-system access.
Why it still matters: It became one of the defining examples of cyber operations causing real-world critical-infrastructure disruption.
Background
ABOUT THE PROJECT

Cyber history as a living reference.

The event corpus is maintained separately in structured XML. This page is the presentation layer. The XML can continue growing without changing the visual taxonomy or editorial standard.

The next integration step is hosting the XML at a stable web endpoint so the page can query it dynamically without relying on inline script execution inside WordPress content.

Editorial standard

Primary and authoritative sources are preferred. Wikipedia is useful background and discovery, not a substitute for stronger evidence when available.