Archive security incidents
xz-utils Backdoor (CVE-2024-3094) (Archive)
A build-time backdoor in liblzma, planted through a multi-year social engineering campaign against a single maintainer, and caught by a performance regression.
By jurisdiction
8 entries in this archive are tagged with International / multiple jurisdictions as their jurisdiction. An event can appear under more than one jurisdiction when its effects cross borders.
Archive security incidents
A build-time backdoor in liblzma, planted through a multi-year social engineering campaign against a single maintainer, and caught by a performance regression.
Archive security incidents
A remotely exploitable JNDI lookup in Apache Log4j 2, the disclosure-to-exploitation window, and the supply chain behind it.
Archive security incidents
A malicious update distributed through SolarWinds Orion, attributed publicly to a named threat actor, and the disclosure that followed.
Archive data breaches
A compromise of the Starwood guest reservation database was disclosed by Marriott after its acquisition of Starwood.
Archive security incidents
The Windows SMB vulnerability that became the most consequential exploited vulnerability of the 2010s, and the two campaigns built on it.
Archive security incidents
A missing bounds check in OpenSSL that let a remote client read process memory, and the two years of unmonitored exploitation it enabled.
Archive research papers
A study of how few location points may be needed to identify people in a mobility dataset.
Archive research papers
A study showing how auxiliary information can be used to re-identify records in a sparse dataset.