Archive-Opsec

Search

/ to open · ↑↓ to move · Enter to open

Indexes guides, archive entries, news, resources and sources. Nothing is sent to a third party.

Archive category

Security Incidents

Vulnerability disclosure, exploitation of widely deployed software, and systemic compromise.

Technical facts are taken from the vendor advisory and the CVE record; impact figures are not estimated here.

Archive confirmed

xz-utils Backdoor (CVE-2024-3094) (Archive)

A build-time backdoor in liblzma, planted through a multi-year social engineering campaign against a single maintainer, and caught by a performance regression.

29 Mar 2024 · unchecked #supply-chain#disclosure#hardening

Archive confirmed

Log4Shell (CVE-2021-44228) (Archive)

A remotely exploitable JNDI lookup in Apache Log4j 2, the disclosure-to-exploitation window, and the supply chain behind it.

10 Dec 2021 · unchecked #supply-chain#ransomware#hardening

Archive confirmed

Colonial Pipeline Ransomware Attack (Archive)

The 7 May 2021 ransomware attack on the operator of the largest US fuel pipeline, the ransom payment, and the recovery of most of it.

7 May 2021 · unchecked #ransomware#critical-infrastructure#supply-chain

Archive confirmed

SolarWinds SUNBURST (Archive)

A malicious update distributed through SolarWinds Orion, attributed publicly to a named threat actor, and the disclosure that followed.

4 Dec 2020 · unchecked #supply-chain#disclosure#mass-surveillance

Archive confirmed

Heartbleed (CVE-2014-0160) (Archive)

A missing bounds check in OpenSSL that let a remote client read process memory, and the two years of unmonitored exploitation it enabled.

7 Apr 2014 · unchecked #supply-chain#encryption#end-to-end-encryption