Archive-Opsec

Search

/ to open · ↑↓ to move · Enter to open

Indexes guides, archive entries, news, resources and sources. Nothing is sent to a third party.

By jurisdiction

International / multiple jurisdictions

8 entries in this archive are tagged with International / multiple jurisdictions as their jurisdiction. An event can appear under more than one jurisdiction when its effects cross borders.

Archive security incidents

xz-utils Backdoor (CVE-2024-3094) (Archive)

A build-time backdoor in liblzma, planted through a multi-year social engineering campaign against a single maintainer, and caught by a performance regression.

29 Mar 2024 · confirmed #supply-chain#disclosure#hardening

Archive security incidents

Log4Shell (CVE-2021-44228) (Archive)

A remotely exploitable JNDI lookup in Apache Log4j 2, the disclosure-to-exploitation window, and the supply chain behind it.

10 Dec 2021 · confirmed #supply-chain#ransomware#hardening

Archive security incidents

SolarWinds SUNBURST (Archive)

A malicious update distributed through SolarWinds Orion, attributed publicly to a named threat actor, and the disclosure that followed.

4 Dec 2020 · confirmed #supply-chain#disclosure#mass-surveillance

Archive data breaches

Marriott Starwood guest database breach (Archive)

A compromise of the Starwood guest reservation database was disclosed by Marriott after its acquisition of Starwood.

30 Nov 2018 · confirmed #breach#travel#data-protection

Archive security incidents

Heartbleed (CVE-2014-0160) (Archive)

A missing bounds check in OpenSSL that let a remote client read process memory, and the two years of unmonitored exploitation it enabled.

7 Apr 2014 · confirmed #supply-chain#encryption#end-to-end-encryption