Archive-Opsec

Search

/ to open · ↑↓ to move · Enter to open

Indexes guides, archive entries, news, resources and sources. Nothing is sent to a third party.

Public record archive

Privacy and security archive

Short, source-linked records of incidents, laws, research, surveillance, and censorship. Each entry shows what is documented and what still needs review.

Browse by category

Latest entries

Archive security incidents

xz-utils Backdoor (CVE-2024-3094) (Archive)

A build-time backdoor in liblzma, planted through a multi-year social engineering campaign against a single maintainer, and caught by a performance regression.

29 Mar 2024 · confirmed #supply-chain#disclosure#hardening

Archive privacy laws

EU Digital Services Act (Regulation 2022/2065) (Archive)

The EU framework for online intermediaries, including conditional liability exemptions, notice and action duties, and restrictions on targeted advertising to minors.

17 Feb 2023 · adopted #data-protection#european-union#transparency

Archive security incidents

Log4Shell (CVE-2021-44228) (Archive)

A remotely exploitable JNDI lookup in Apache Log4j 2, the disclosure-to-exploitation window, and the supply chain behind it.

10 Dec 2021 · confirmed #supply-chain#ransomware#hardening

Archive security incidents

Colonial Pipeline Ransomware Attack (Archive)

The 7 May 2021 ransomware attack on the operator of the largest US fuel pipeline, the ransom payment, and the recovery of most of it.

7 May 2021 · confirmed #ransomware#critical-infrastructure#supply-chain

Archive corporate privacy

Apple App Tracking Transparency (Archive)

Apple introduced a permission requirement for app tracking across companies and access to the advertising identifier.

Apr 2021 · adopted #tracking#advertising#data-minimisation

Archive security incidents

SolarWinds SUNBURST (Archive)

A malicious update distributed through SolarWinds Orion, attributed publicly to a named threat actor, and the disclosure that followed.

4 Dec 2020 · confirmed #supply-chain#disclosure#mass-surveillance

Archive privacy laws

US State Privacy Laws (Archive)

The wave of US state comprehensive privacy statutes from 2020, and what differs between them.

3 Nov 2020 · adopted #data-protection#united-states#data-broker

Archive data breaches

Marriott Starwood guest database breach (Archive)

A compromise of the Starwood guest reservation database was disclosed by Marriott after its acquisition of Starwood.

30 Nov 2018 · confirmed #breach#travel#data-protection

Archive privacy laws

Schrems II (Case C-311/18) (Archive)

The Court of Justice judgment that invalidated the EU-US Privacy Shield and required a case-by-case assessment of transfers to the United States.

16 Jul 2018 · adopted #data-protection#european-union#transfers

Archive data breaches

Equifax 2017 data breach (Archive)

A 2017 intrusion into Equifax systems exposed personal information held by the credit reporting company.

Sep 2017 · confirmed #breach#data-protection#united-states