Research
203 articles - malware analysis, major incidents, hardware hacking, threat intelligence, underground history
The 2007 Estonian Cyberattacks: The First Nation-State DDoS Campaign and the Birth of NATO Cyber Defence
In April 2007, Estonia became the first nation-state subjected to a sustained DDoS campaign against its entire digital infrastructure - parl…
SQL Slammer: The 376-Byte Worm That Infected 75,000 Servers in 10 Minutes and Is Still the Fastest Malware Ever
At 05:30 UTC on January 25, 2003, SQL Slammer began spreading. By 05:40 it had doubled in size seven times. By 06:00, 75,000 servers were in…
Georgia 2008: The First Cyberattacks Synchronized with a Conventional Military Invasion
When Russian tanks crossed into South Ossetia on August 8, 2008, DDoS attacks against Georgian government websites had already been running …
APT10 Cloud Hopper: How China Compromised 45 MSPs to Reach Hundreds of Their Clients Simultaneously
APT10, attributed to China's MSS Tianjin Bureau, compromised 45 managed service providers across 12 countries between 2016-2018 - not to ste…
Nimda: The Worm That Used Five Propagation Vectors Simultaneously and Became the Internet's Top Threat in 22 Minutes
Released September 18, 2001 - exactly one week after 9/11 - Nimda combined five separate propagation vectors: email MIME exploit, IIS buffer…
GhostNet: The Chinese Espionage Network That Compromised 1,295 Computers in 103 Countries and Could Watch Through Your Webcam
In 2009, Citizen Lab researchers investigating malware on Tibetan government-in-exile computers discovered a Chinese cyber espionage network…
Blaster: The Worm That Attacked Windows Update While Telling Bill Gates to Fix His Software
Blaster appeared August 11, 2003, exploiting a Windows RPC DCOM buffer overflow patched 26 days earlier. It infected millions of machines, f…
Triton: The Russian Malware Designed to Disable Safety Systems and Allow Industrial Explosions
In 2017, malware was found inside a Schneider Electric Triconex safety system at a Saudi petrochemical plant - the first time malware had ta…
Vault 7: When WikiLeaks Published the CIA's Entire Hacking Toolkit and a Spy Went to Prison for 40 Years
In March 2017, WikiLeaks published 8,761 CIA documents exposing iOS exploits, Android backdoors, a Samsung TV covert recording tool, and the…