Cybersecurity

The history of computer security, from the first ARPANET log entry in October 1969 to the ransomware economy and AI-assisted attacks of the 2020s — worms, the crypto wars, the hacker underground, nation-state operations, mass surveillance and the people who defended against all of it.

A chronological documentary of 244 moments spanning 1969–2026 on Loreline.

last updated 2026-08-08

Eras

  1. The BBN IMP team, 1969. The BBN engineering team that built the first ARPANET routers, including Robert Kahn, Frank Heart, Severo Ornstein and Will Crowther. These are the people who built the substrate on which the first worm ran two years later. Released under CC0 on Commons.
  2. The 1969 BBN Interface Message Processor. A Bolt Beranek and Newman Interface Message Processor, the refrigerator-sized packet switch that formed each ARPANET node. Creeper (1971) moved between TENEX systems attached to exactly this hardware. File DateTimeOriginal is 2017, so this is a museum-era photograph of a period machine. The subject dates from 1969; the photograph itself is later.
  3. The first ARPANET log entry, 29 October 1969. The handwritten IMP log from UCLA recording the first host-to-host login over the ARPANET, the network on which Creeper would later propagate. Charles S. Kline's entry notes that the system crashed after two characters of 'LOGIN'. This is the founding document of the network whose openness every later attack depended on.
  4. A DEC PDP-10 / DECSYSTEM-10, the machine Creeper ran on. Creeper was written by Bob Thomas at BBN in 1971 for the TENEX operating system running on DEC PDP-10 hardware, printing 'I'M THE CREEPER: CATCH ME IF YOU CAN'. This is a preserved DECSYSTEM-10 at the Living Computer Museum in Seattle. There is no known free photograph or screenshot of Creeper itself. The subject dates from 1971; the photograph itself is later.
  5. A Cap'n Crunch 2600 Hz whistle, Deutsches Technikmuseum. The actual cereal-box whistle displayed as a museum object in Berlin. Holding the real, cheap plastic object next to the phone system it defeated is the whole point of the phreaking story. The 2600 Hz exploit was publicised by Ron Rosenbaum's 1971 Esquire article 'Secrets of the Little Blue Box'. The subject dates from 1971; the photograph itself is later.
  6. A blue box at the Computer History Museum. A blue box: a hand-built tone generator that reproduced the multi-frequency signalling AT&T used internally, giving its user free worldwide calls. Wozniak and Jobs built and sold these before Apple existed. Photographed at the Computer History Museum in 2004. The subject dates from 1972; the photograph itself is later.
  7. Whitfield Diffie and Martin Hellman. whose 1976 paper 'New Directions in Cryptography' introduced public-key exchange and made civilian cryptography possible. Everything in the crypto wars, and every HTTPS session, descends from that paper. Commons carries no date for this file. The subject dates from 1976; the photograph itself is later.
  8. Apple I, Macintosh and a Wozniak blue box together. A museum case placing a blue box beside the Apple I and the Macintosh. Wozniak has said repeatedly that without the blue box there would have been no Apple: the pair's first product was an illegal one. It is the clearest single image of the line from phreaking to personal computing. The subject dates from 1976; the photograph itself is later.
  9. ARPANET logical map, March 1977, PDP-10 nodes highlighted. The Computer History Museum's reproduction of the ARPANET logical map for March 1977 with PDP-10 systems marked. It shows how small and how completely trusted the early network was: a few dozen named hosts with no authentication boundary between them. This is the topology Creeper and, later, the Morris Worm traversed.
  10. An acoustic coupler modem. An acoustic coupler: the handset of an ordinary telephone is pushed into two rubber cups and data is carried as audible tone. This is how a home hobbyist got onto a remote system before dedicated data lines, and it is the device behind almost every 1980s war-dialling story. Slow, noisy and completely unauthenticated. The subject dates from 1978; the photograph itself is later.
  11. A 1978 interview with John Draper. A contemporaneous interview in which Draper demonstrates a colour graphics computer costing 1,500 dollars, plays an early Lunar Lander game and discusses his work. It is a rare period recording of a phreaker at the moment personal computing arrived.
  12. CBS Nightwatch on computer security after WarGames. A 1983 CBS Nightwatch segment on computer safety, hackers and the 414s, broadcast after the group's intrusions into systems including Los Alamos National Laboratory and while WarGames had made nuclear-command fears mainstream. Period television coverage of the first hacking panic.
  13. A Cray-1 supercomputer. A Cray-1, the machine that defined what 'the big computer' looked like to the public in the WarGames era. WarGames (1983) put the idea of a teenager dialling into a military system in front of a mass audience, and led directly to congressional hearings. No frame of the film itself is freely licensed. The subject dates from 1983; the photograph itself is later.
  14. A Bildschirmtext advertisement. A short television advertisement for Bildschirmtext, the interactive online service introduced by the Deutsche Bundespost in 1983 for news, ordering and home banking. It shows how the system was sold to the public shortly before the Chaos Computer Club demonstrated its weaknesses.
  15. Computer enthusiasts gather in Hamburg, 1984. Archive television footage of young computer fans meeting at the Bürgerhaus Eidelstedt in Hamburg just after Christmas 1984, described in the report as looking for security holes. It is period footage of the earliest Chaos Computer Club gatherings.
  16. The Btx hack on ZDF heute journal. German television reports on the Chaos Computer Club's demonstration against the Bildschirmtext system, in which the club moved about 130,000 marks from a Hamburg savings bank account overnight on 16 to 17 November 1984. The report brought the young club to national attention.
  17. Wau Holland at the DAFTA data-protection conference. ZDF's heute journal reports from the eighth DAFTA data protection conference and interviews Wau Holland about the relationship between hackers and data protection. The uploader describes it as probably the first mention of the Chaos Computer Club on German television.
  18. Protek 1200 acoustic coupler, 1984. The retail box for a 1984 UK acoustic coupler modem, from a private retro-computing collection. Period packaging is often more evocative than the device: it shows the moment home dial-up access became a consumer product. 1200 baud was fast for a bedroom in 1984. The subject dates from 1984; the photograph itself is later.
  19. NSA headquarters, Fort Meade, from the air. Trevor Paglen's aerial photograph of NSA headquarters at Fort Meade, released CC0. It stands in for the institutional side of the story: the 1986 Computer Fraud and Abuse Act, the Computer Security Act of 1987, and the agency that would sit at the centre of the crypto wars and the 2013 disclosures. Ronald Reagan dedicated the new NSA operations buildings in September 1986. The subject dates from 1986; the photograph itself is later.
  20. Cliff Stoll, who traced the Cuckoo's Egg intrusion. Cliff Stoll, the Berkeley astronomer who chased a 75-cent accounting discrepancy in 1986 and uncovered a KGB-paid West German intruder inside US military networks. His account, The Cuckoo's Egg, is the first real-time narrative of a computer intrusion investigation. Photographed at a security conference in 2017. The subject dates from 1986; the photograph itself is later.
  21. Information overload in Hackers: Wizards of the Electronic Age. A clip from the 1986 documentary Hackers: Wizards of the Electronic Age, in which computer users describe being overwhelmed by the volume of information available to them. It is period footage of the community that formed around early personal computing.
  22. The Morris Worm source code on a floppy disk, museum exhibit. The floppy disk holding the source of the Morris Worm, displayed at the Museum of Science in Boston. Released on 2 November 1988, it infected roughly 6,000 machines, about ten percent of the internet, by re-infecting hosts it had already taken. The response created CERT/CC at Carnegie Mellon within weeks. The subject dates from 1988; the photograph itself is later.
  23. Robert Tappan Morris. then a Cornell graduate student, who wrote and released the 1988 worm and became the first person convicted under the 1986 Computer Fraud and Abuse Act. He was later a co-founder of Y Combinator and an MIT professor. Photographed in 2008. The subject dates from 1988; the photograph itself is later.
  24. Boston television news report on the 1988 worm outbreak. A local Boston news report from 1988 covering the computer worm that disrupted machines across the early internet, complete with interviews and stock game footage used to illustrate what a virus was. It is one of the earliest surviving examples of mainstream broadcast television trying to explain malicious code to a general audience.
  25. Hackers in Switzerland, 1989. Swiss television reports on the hacker scene that emerged alongside the arrival of personal computers in the workplace during the 1980s, and on young people repeatedly breaking into supposedly secure systems. The item is drawn from the SRF archive.
  26. Phil Zimmermann, portrait. A close portrait of Phil Zimmermann, licensed by Zimmermann himself for encyclopaedic use. PGP's release in 1991 is the moment strong public-key cryptography escaped governments and banks and reached ordinary people. Note the file's own date is 2010. The subject dates from 1991; the photograph itself is later.
  27. The MYK-78 Clipper chip. The actual NSA-designed MYK-78 'Clipper' chip, photographed and released CC BY by researcher Travis Goodspeed. Announced in 1993, Clipper would have encrypted phone calls while escrowing a key for law enforcement. Matt Blaze found a flaw in its LEAF checksum in 1994 and public opposition killed it, setting the terms of every backdoor debate since. The subject dates from 1993; the photograph itself is later.
  28. The 2600 panel at the first HOPE conference. The 2600 panel recorded at Hackers On Planet Earth on 13 August 1994, in which the magazine's staff discuss how it started, the lawsuits and letters it attracted, and the people behind the pseudonyms. It is a primary record of the first HOPE and of hacker publishing in the early nineties.
  29. The information highway: security, commerce and democracy. A panel including David Farber and Barbara Simons debates security, commerce and democratic accountability on the emerging information highway. It captures the policy assumptions in circulation just as the crypto wars were opening.
  30. Cryptography and privacy at the first HOPE. Bob Stratton introduces cryptography and privacy to the audience of the first Hackers On Planet Earth conference in New York. The talk sets out the terms of the public policy fight over encryption as it stood in 1994.
  31. European hackers at the first HOPE. A panel of European hackers, including figures from the Chaos Computer Club and the Dutch Hack-Tic scene, describe their communities to an American audience for the first time. It was recorded at the first Hackers On Planet Earth conference.
  32. Boxed Netscape Navigator, Computer History Museum. Retail-boxed Netscape Navigator in the Computer History Museum collection. Netscape shipped SSL in 1994-95, putting encryption into an ordinary consumer product for the first time; SSL 3.0 in 1996 is the direct ancestor of TLS and of the padlock icon. Export rules meant the international build was deliberately crippled to 40-bit keys. The subject dates from 1995; the photograph itself is later.
  33. The 'FREE KEVIN' bumper sticker. The yellow FREE KEVIN sticker produced by 2600 magazine during Kevin Mitnick's four and a half years of pre-trial detention after his 1995 arrest. It became the visual shorthand for a hacker community that felt the state was wildly overreacting. The design itself dates from the 1990s.
  34. Phone hackers on BBC's The Net. A segment from the BBC series The Net on the harassment of writers Josh Quittner and Michelle Slatalla, whose phone line was attacked after they wrote about the New York hacking group Masters of Deception. It documents the reprisal culture of the early 1990s scene.
  35. Session transcripts from the Kevin Mitnick investigation. A long screen capture of the session transcripts associated with the tracking of Kevin Mitnick, annotated with timestamps by the uploader. Raw material rather than narrative: the logs themselves, as they were presented.
  36. A rack-mounted Cisco PIX 515 firewall. A Cisco PIX, the appliance that made the dedicated network firewall a normal thing to buy rather than a research idea. Cisco acquired the PIX in 1995 and it dominated the perimeter through the late 1990s, the years when 'security' still largely meant 'a hard shell around a soft network'. The subject dates from 1996; the photograph itself is later.
  37. Netscape Navigator 2.02. A screenshot of Netscape Navigator 2.02, the browser generation in which SSL became routine. Period software screenshots are scarce under free licences, so this CC0 capture is worth keeping even though it was taken in 2015 on Windows XP. The subject dates from 1996; the photograph itself is later.
  38. Wau Holland interviewed in Amsterdam. Chaos Computer Club co-founder Wau Holland is interviewed for Kleurnet television in Amsterdam about hacking, networks and the club's outlook. Holland was the movement's most quoted spokesman until his death in 2001.
  39. The L0pht hackers testify before the US Senate, 1998. Full footage of the 19 May 1998 hearing before the Senate Committee on Governmental Affairs, at which seven members of the Boston hacker collective L0pht testified under their handles - Mudge, Brian Oblivion, Kingpin, Tan, Space Rogue, Weld Pond and Stefan von Neumann. It is the moment the underground and US legislators spoke to each other on the record.
  40. Source code of the Melissa macro virus. An excerpt of the Word macro source of Melissa, released 26 March 1999, which mailed itself to the first fifty entries in each victim's Outlook address book. It forced Microsoft and others to shut down mail gateways entirely and is the first mass-mailing worm with real economic cost. Released CC0. The subject dates from 1999; the photograph itself is later.
  41. Arrest in the Melissa virus investigation. Associated Press footage from 3 April 1999 reporting the arrest and charging of a man over the Melissa email virus, tracked down with help from America Online technicians and a computer task force. It documents an early example of industry and law enforcement working a malware case together.
  42. Court appearance of the man accused of writing Melissa. Associated Press footage from 9 April 1999 of David Smith, aged thirty, appearing in court charged with interrupting public communications, conspiracy and theft of a computer service in connection with the Melissa virus. Among the earliest courtroom footage of a malware prosecution.
  43. Back Orifice 2000 behind the scenes at DEF CON 7. Footage shot inside the Cult of the Dead Cow's suite in the hours before the group released Back Orifice 2000 at DEF CON 7 in Las Vegas. The tape sat unreleased for twenty years before cDc published it. First-hand documentation of a defining moment in hacker-group culture and remote-administration tooling.
  44. Wau Holland at the first Chaos Communication Camp. Wau Holland gives his assessment of the first Chaos Communication Camp at Altlandsberg and of what the hacker movement had and had not achieved. The camp established the CCC's outdoor gathering as a fixture.
  45. The ILOVEYOU / Love Letter worm. The Love Letter worm, sent from Manila on 4 May 2000 as an attachment named LOVE-LETTER-FOR-YOU.TXT.vbs. It overwrote files and re-mailed itself to every Outlook contact, hitting tens of millions of machines within days; the Philippines had no law to charge the author under. It is the moment social engineering beat technical controls at global scale. The subject dates from 2000; the photograph itself is later.
  46. Brazilian TV news report on the ILOVEYOU virus. A Jornal da Globo report from 2000 covering the ILOVEYOU mail worm as it spread through Windows machines worldwide. Period Brazilian broadcast coverage of the outbreak.
  47. German TV warning about the ILOVEYOU worm. A tagesschau bulletin broadcast on 4 May 2000, the day the ILOVEYOU worm spread explosively by email across Europe. Period German broadcast coverage, re-posted twenty years later.
  48. Television special report on Kevin Mitnick. A broadcast special report on Kevin Mitnick, made around the time of his release, covering the pursuit, the 1995 arrest and the sentence. Period television treatment of the case that shaped the public image of hacking.
  49. Freedom Downtime premieres at 17C3. The first showing of 2600's documentary Freedom Downtime, on the Free Kevin Mitnick campaign, followed by a talk from the magazine's editor Eric Corley. It was presented at the seventeenth Chaos Communication Congress.
  50. Phil Zimmermann on The Screen Savers. TechTV's The Screen Savers interviews Phil Zimmermann about Pretty Good Privacy, the encryption program he released in 1991. Zimmermann describes how publishing strong cryptography brought him to the attention of the US government.
  51. Steven Levy on the end of privacy. Journalist Steven Levy discusses Crypto, his account of how a loose group of researchers and activists forced strong encryption into public hands against government resistance. The talk was given at the 92nd Street Y around the book's publication.
  52. Investigation into the origin of the Code Red worm in China. Associated Press footage from 3 September 2001 from a university computer department in China, filmed as investigators looked into where the Code Red worm was written. Early evidence of how transnational a worm investigation had already become.
  53. Code Red cleanup tool on The Screen Savers. Bob Lee appears on TechTV's The Screen Savers to discuss a program he wrote to stop the spread of the Code Red worm. The segment captures the improvised, self-help response of the technical community during the 2001 outbreak, when patching lagged far behind infection.
  54. CNN interview on the Nimda worm. A CNN Financial News interview recorded on 18 September 2001, a day after the Nimda worm began spreading through Windows systems and web servers. Contemporaneous broadcast footage of the response to a mass-malware outbreak, uploaded years later by the interviewee.
  55. CNN interview on internet security during the Code Red outbreak. A CNN interview with Aled Miles on internet security in the middle of the Code Red worm outbreak. Period coverage of how the security industry addressed a fast-spreading worm.
  56. FBI press conference on the Code Red worm. Associated Press footage from a press conference on 30 July 2001 including Ron Dick, head of the FBI's National Infrastructure Protection Center, describing Code Red as the latest in a series of worms used to launch distributed attacks. A rare on-camera record of the federal response as the outbreak was under way.
  57. Adrian Lamo. the 'homeless hacker' who broke into The New York Times and Microsoft from public library terminals. In 2010 he reported Chelsea Manning to the US Army, splitting the hacker community and prefiguring the Snowden argument three years later. Cropped from a group photograph taken around 2001.
  58. Adrian Lamo, Kevin Mitnick and Kevin Poulsen, c. 2001. The three best-known American hackers of their generation photographed together around 2001: Adrian Lamo, Kevin Mitnick and Kevin Poulsen. Poulsen had rigged radio-station phone lines to win a Porsche; Mitnick had just come off supervised release; Lamo would later report Chelsea Manning to the FBI. All three ended up on the other side of the fence.
  59. The Secret History of Hacking. A documentary on phreaking, computer hacking and social engineering from the 1970s to the 1990s, featuring John Draper, Steve Wozniak and Kevin Mitnick. It traces the line from blue boxes to the press panic over insecure computer systems.
  60. Cult of the Dead Cow activism panel at DEF CON 9. The Cult of the Dead Cow's panel on hacktivism at DEF CON 9, held in Las Vegas in July 2001. The group used its DEF CON appearances to argue that hacking tools and techniques could serve human rights work.
  61. PBS Frontline: Hackers. The full 2001 Frontline documentary on computer intrusion, profiling self-described hackers and the investigators pursuing them at the point where network crime was becoming a mainstream concern. A period broadcast documentary preserved by an archival channel.
  62. Phil Zimmermann speaking at HAL 2001. Phil Zimmermann, author of PGP, lecturing at the Hackers At Large camp in Enschede in August 2001. Zimmermann released PGP free in 1991 and spent three years under federal criminal investigation for 'munitions export' because strong cryptography was legally a weapon. The case was dropped in 1996 and effectively ended US export controls on civilian crypto.
  63. Mikko Hypponen. of F-Secure, one of the few researchers who worked through the whole worm era and is still a public voice in the ransomware one. F-Secure's analyses of Melissa, Slammer, Sasser and later Stuxnet ran in real time. Released CC0 by Hypponen himself.
  64. Information security before and after public-key cryptography. Whitfield Diffie traces information security through the twentieth century and the transformation brought by public-key cryptography in the 1970s. He treats the discovery as a break with centuries of key distribution practice.
  65. Michael Lynn presenting the Cisco IOS flaw, Black Hat 2005. Michael Lynn on stage at Black Hat on 27 July 2005, having resigned from ISS that morning so he could demonstrate remote code execution on Cisco IOS routers. Cisco had the printed slides torn out of every conference programme and sued; the talk became the defining case in the disclosure-versus-suppression fight.
  66. Project Blinkenlights at 22C3, Berlin, 2005. The Chaos Computer Club's Blinkenlights installation at the 22nd Chaos Communication Congress in Berlin, December 2005. The CCC, founded in 1981, is the oldest and most politically serious hacker organisation in Europe, and its annual congress predates DEF CON by more than a decade.
  67. Riots over the Bronze Soldier, Tallinn, 26 April 2007. Night-time protests in Tallinn over the relocation of the Bronze Soldier war memorial, 26 April 2007. Within hours Estonia's banks, ministries, parliament and newspapers were knocked offline by three weeks of distributed denial-of-service traffic. It is generally treated as the first case of a nation-state-scale cyber attack against a whole country, and led directly to NATO siting its cyber defence centre in Tallinn.
  68. Bruce Schneier at CFP 2007. Bruce Schneier, author of Applied Cryptography and the person who did most to move the public conversation from 'ciphers' to 'systems and incentives'. His phrase 'security theatre' entered general use after 2001. Photographed on a net-freedom panel in 2007.
  69. Whit Diffie at Computers, Freedom and Privacy 2007. Diffie at the Computers, Freedom and Privacy conference in 2007. CFP was where cryptographers, lawyers and civil-liberties groups fought out the policy side of security through the 1990s and 2000s.
  70. Phil Zimmermann on VoIP encryption at Stanford. Zimmermann lectures at the Stanford Computer Systems Colloquium on encrypting voice over IP and on how the encryption debate had shifted since the 1990s. He describes the move from a civil liberties argument to one framed around surveillance.
  71. The RSA Conference Cryptographers' Panel, 2008. The 2008 RSA Conference cryptographers' panel: Whitfield Diffie, Martin Hellman, Ron Rivest, Adi Shamir and Burt Kaliski on one stage. Between them they invented public-key exchange and RSA. This annual panel is the closest thing the field has to a state-of-the-union.
  72. A brief history of phone phreaking, at The Last HOPE. A conference talk from The Last HOPE on 19 July 2008 covering phone phreaking from 1960 to 1980, the golden age of the analogue long-distance network, and the origin of the blue box. It reconstructs the technical substrate that made phreaking possible.
  73. Spread of the Conficker worm. A contemporaneous map of Conficker's spread, drawn in January 2009. Conficker exploited MS08-067 and built a botnet of millions of hosts with a domain-generation algorithm that defeated simple takedowns. It provoked the Conficker Working Group, the first large industry-wide coordinated defence.
  74. Melissa macro virus running on a test machine. A screen recording showing the Melissa macro virus executing: it mails itself to contacts in the address book and infects further Word documents. Demonstrations like this preserve the behaviour of malware long after the platforms it targeted are gone.
  75. Associated Press report on Conficker before April 1. An Associated Press wire report filed on 31 March 2009, the day before Conficker's much-anticipated 1 April activation date. It conveys the uncertainty of the moment: millions of infected PCs, and no agreement on what the worm would actually do.
  76. CNN on whether Conficker would strike. CNN's John Sutter is interviewed on the eve of Conficker's 1 April 2009 trigger date about what the worm might do. The segment documents the media build-up around a date that ultimately passed with little visible effect.
  77. CBS News on Conficker's later variants. Harry Smith speaks with CNET's Natali Del Conte about Conficker continuing to morph and spread, and its shift toward identity theft. The segment shows how the story moved from a single trigger date to an ongoing criminal infrastructure problem.
  78. The Natanz enrichment facility, Iran. The Natanz fuel enrichment plant, the target of Stuxnet. Roughly a thousand IR-1 centrifuges were destroyed or replaced in 2009-2010. Photographed in 2022, so this is a modern view of the site rather than a period image. The subject dates from 2010; the photograph itself is later.
  79. A Siemens Simatic S7-300 PLC, Stuxnet's target. The Siemens Simatic S7-300 programmable logic controller, the class of industrial device Stuxnet was built to reprogram. Stuxnet altered centrifuge motor speeds at Natanz while replaying normal readings to the operators. This is the moment malware stopped being about data and started breaking physical machinery. The subject dates from 2010; the photograph itself is later.
  80. Global distribution of Stuxnet infections. A map of where Stuxnet was actually found, overwhelmingly concentrated in Iran. The distribution was one of the first public clues that this was a targeted weapon rather than criminal malware.
  81. Distributed FPGA number crunching at 27C3. Felix Domke shows how commodity FPGAs can reproduce the brute-force capability of the EFF's Deep Crack machine, which walked the 56-bit DES keyspace in 1998 at a cost of 250,000 dollars. The talk measures how far the economics of key search had moved in twelve years.
  82. Trailer for the hacking documentary Code 2600. The official trailer for Code 2600, a feature documentary by Jeremy Zerechak on the rise of the information age and the hacker culture that grew alongside it. It is a short montage rather than the full film.
  83. Kevin Mitnick demonstrating a keylogger, Campus Party 2010. Mitnick after his reinvention as a security consultant, holding up a hardware keylogger at Campus Party 2010. His talk was on social engineering, the technique that actually got him into most systems: he talked his way in far more often than he broke in. The image documents how the 1990s outlaw became the industry's most bookable speaker.
  84. How Stuxnet hid its own code from the operator. A contemporaneous technical diagram showing Stuxnet intercepting the engineering workstation's view of the PLC so its injected STL code stayed invisible. This rootkit-for-industrial-control behaviour is what made Stuxnet a decade ahead of anything else in 2010.
  85. Akte CCC: the history of the Chaos Computer Club. A German documentary tracing the Chaos Computer Club from a group dismissed as freaks in the 1980s to an organisation cited in constitutional court proceedings. It covers the club's shift from stunts to expert testimony.
  86. Searching for the authors of the Brain virus. Mikko Hypponen travels to Lahore to find Amjad and Basit Farooq Alvi, the brothers who wrote Brain, the first PC virus, which spread on floppy disks from 1986. It is their first video interview about it.
  87. Eric Corley (Emmanuel Goldstein) at Chaos Communication Camp 2011. Eric Corley, who publishes 2600 under the name Emmanuel Goldstein, speaking at Chaos Communication Camp in 2011. He was the defendant in Universal v. Reimerdes, the first major DMCA case, over publishing the DeCSS DVD descrambler.
  88. Freedom Downtime, the 2600 film about Kevin Mitnick. The complete 2600 Films documentary on Kevin Mitnick, who was held for nearly five years without bail, and on the Free Kevin campaign that grew around his case. Directed by Emmanuel Goldstein, it is a first-hand record of the hacker community arguing its own case.
  89. The 2600 telephone-company van. 2600's modified New York Telephone van at the 2011 Maker Faire, a joke about the social engineering technique of simply dressing as the phone company and walking in. It is the phreaking era's sense of humour preserved intact.
  90. Disinformation, a short film on the Cult of the Dead Cow. An eleven-minute documentary portrait of the American hacker group Cult of the Dead Cow, whose members discuss Back Orifice 2000 and its effect on the security industry. The film shows the group demonstrating remote control of a Windows machine.
  91. RSA Conference 2012 keynote on client-to-cloud security. Intel's Pranav Mehta delivers an RSA Conference 2012 keynote on securing systems from the client through to the cloud. A period artifact of how the security industry framed its priorities as workloads moved off the endpoint.
  92. We Are Legion, the hacktivism documentary. Brian Knappenberger's feature documentary on hacktivism and the rise of Anonymous, built from interviews with participants and observers. It traces the collective from imageboard pranks through Project Chanology and the payment-processor campaigns.
  93. Black Hat Briefings at Caesars Palace, 2012. The 15th Black Hat Briefings at Caesars Palace in Las Vegas, 2012. Black Hat is the commercial half of the Las Vegas security week that DEF CON began: same city, same researchers, corporate budgets.
  94. The Diffie-Hellman key exchange. A short animated account of how two parties can agree on a shared secret in the open, and of the history behind public key cryptography. It explains the idea that made encrypted communication between strangers possible.
  95. Edward Snowden in Hong Kong, 6 June 2013. Edward Snowden photographed by Laura Poitras at the Mira Hotel in Hong Kong during the interview that introduced him to the world. The disclosures that began that week documented PRISM, XKeyscore, bulk metadata collection and the deliberate weakening of cryptographic standards. It is the single most consequential security story of the period.
  96. The PRISM cover slide. The cover slide of the NSA's internal PRISM briefing, published on 6 June 2013, listing the nine providers whose data the programme reached. Its clip-art design became famous precisely because it looked so mundane. As a US government work it is public domain.
  97. First reports of the Target payment card breach. Local news coverage from 19 December 2013, the day the Target breach became public. Early reporting of the intrusion that put card-data theft at retail scale onto the front page.
  98. Extended local coverage of the Target breach. A longer WPRI segment on the Target security breach as the story broke, covering what shoppers were being told and what remained unknown. Shows the immediate consumer-facing confusion around a large card breach.
  99. Target sets up a hotline for affected shoppers. Coverage of Target's response to the breach, including a hotline for customers who believed their card details had been compromised. A record of corporate incident response as it looked to the public.
  100. Snowden interviewed by Glenn Greenwald in Hong Kong. The Guardian's filmed interview in which Edward Snowden explains to Glenn Greenwald why he leaked NSA documents, including the line about not wanting to live in a society that does these sorts of things. It is the primary on-camera source for his stated motives.
  101. The Guardian on questions raised by the NSA revelations. Guardian journalist Nick Hopkins sets out the open questions raised by the latest documents from Edward Snowden, including how much money passed between agencies. A short newsroom piece from the middle of the disclosure sequence.
  102. Report on the NSA collecting email and messaging contact lists. A news report on the Washington Post's story that the NSA had been collecting contact lists from personal email and instant messaging accounts, based on documents provided by Edward Snowden. One of the many distinct programmes revealed during 2013.
  103. Edward Snowden identified as the source of the NSA leaks. An ABC News webcast reporting that Edward Snowden had come forward as the source behind the NSA disclosures. It marks the moment the story acquired a name and a face.
  104. Has the NSA won the crypto wars?. A policy panel convened after reporting alleged that the NSA had weakened commercial products and cryptographic standards. Panelists debate what the disclosures mean for trust in security engineering.
  105. Our World: Meet the Hackers. A BBC Our World documentary in which Susan Watts meets a young member of LulzSec and traces how he was drawn into a life lived almost entirely online. It is the closest thing to a first-hand television account of the LulzSec period.
  106. Hacking the Czech parliament by SMS, 30C3. A Chaos Communication Congress talk on flaws that allowed the speaker to interfere with systems used by the Czech parliament through text messages. A raw congress recording.
  107. PRISM tasking process slide. The slide describing how an analyst tasked a PRISM selector and how the request flowed through the FBI's interception unit to the provider. Useful when the archive needs to show mechanism rather than outrage.
  108. Snowden receives the Sam Adams award, Moscow, 9 October 2013. Snowden in Moscow in October 2013 accepting the Sam Adams award for Intelligence Integrity, his first appearance after leaving the Hong Kong hotel. It marks the transition from source to exile.
  109. BBC explainer on what Snowden revealed. An illustrated BBC News explainer summarising what the Snowden documents alleged, made at the end of 2013. Useful as a contemporaneous summary of how the revelations were being understood at the time.
  110. NSA ANT catalogue page: JETPLOW implant for Cisco firewalls. A page from the NSA's ANT catalogue, published in December 2013, describing JETPLOW, a persistent firmware implant for Cisco PIX and ASA firewalls. It is the plainest evidence that the security appliance industry's own products were systematically subverted. US government work, public domain.
  111. Kevin Poulsen. once 'Dark Dante' and the first American hacker banned from touching a computer, later an editor at Wired and co-creator of the SecureDrop whistleblower system. His arc is the clearest example of the 1990s hacker-to-journalist pipeline.
  112. The Heartbleed logo. designed at Codenomicon and released CC0 alongside the April 2014 disclosure of CVE-2014-0160. A missing bounds check in OpenSSL's heartbeat extension let anyone read 64KB of server memory at a time, including private keys. Heartbleed is where branded vulnerabilities began, and the logo is itself the historical artifact.
  113. Vanity Fair's animated account of the Snowden affair. An animated condensation of Vanity Fair's long-form article on Edward Snowden, framing the argument over whether he was a whistleblower or a traitor. A retrospective made less than a year after the leaks began.
  114. Running the Heartbleed exploit code, on Computerphile. Dr Steven Bagley walks through the actual code that exploits the Heartbleed bug and runs it, showing what memory comes back. One of the clearest contemporaneous technical explanations of the flaw.
  115. Sony Pictures Entertainment, Culver City. The Sony Pictures offices in Culver City. In November 2014 the Guardians of Peace, later attributed by the FBI to North Korea, wiped Sony's systems and dumped internal email, salaries and unreleased films. It was the first major breach whose primary weapon was public humiliation rather than theft. The subject dates from 2014; the photograph itself is later.
  116. CNN on the Sony Pictures leaks and the studio's damage control. CNN's Pamela Brown reports on the Sony Pictures attack and the executives' attempts at damage control as more internal material was published. Contemporaneous coverage of an incident that redefined what a breach could cost.
  117. CBS Evening News on the continuing Sony disclosures. CBS Evening News covers another round of disparaging emails taken from Sony's network, and asks public relations specialists how a company recovers from such an exposure. The breach as a corporate communications crisis.
  118. Tobias Engel on locating and tracking phones through SS7. A talk at the 31st Chaos Communication Congress showing how the SS7 signalling network can be used to locate a phone number to within tens of metres, intercept traffic and manipulate subscribers. It made telecom signalling security a mainstream concern.
  119. Snowden revelations honoured at the Crunchies awards. Trevor Timm accepts a social impact award on behalf of Edward Snowden at the 2013 Crunchies, with the ceremony tied to an internet protest against mass surveillance. A snapshot of how parts of the technology industry positioned themselves after the leaks.
  120. Heartbleed causes, implementation and timeline, at NISC 2014. A conference presentation delivered on 14 May 2014 covering how the Heartbleed bug came to be written, how the flawed implementation worked, and the timeline of its discovery and disclosure. Longer and more technical than the news-cycle explainers.
  121. Dan Geer's Black Hat keynote on cybersecurity as realpolitik. Dan Geer's keynote at Black Hat USA 2014, arguing that security is a matter of power and policy rather than wishes for safety or order, and proposing a set of concrete policy positions. One of the most cited conference talks in the field.
  122. Cindy Cohn on the second crypto war. EFF legal director Cindy Cohn argues that efforts to weaken encryption leave everyone less secure. She draws on the organisation's litigation history from the first crypto war of the 1990s.
  123. The NSA Utah Data Center, Bluffdale. The NSA's Utah Data Center photographed from an EFF airship in June 2014. Built to store bulk collection at exabyte scale, it became the physical symbol of the Snowden disclosures. Released CC0 by the Electronic Frontier Foundation.
  124. HOPE X conference badge, 2014. The badge from the tenth Hackers On Planet Earth conference in New York, July 2014. HOPE is run by 2600 magazine and is the direct institutional descendant of the phone-phreak scene that opens this archive.
  125. The Shellshock bug explained. Tom Scott explains the Shellshock bug in Bash, a flaw in how the shell handled environment variables that left large numbers of internet-facing systems exploitable. Recorded within days of the vulnerability becoming public.
  126. What the Sony Pictures hack was really about. An AJ+ explainer covering the Sony Pictures intrusion beyond the leaked celebrity emails: threats against employees, the pulled release of a film, and the White House treating the incident as a national security matter. The report notes the attribution to North Korea that officials had made.
  127. NDR revisits the 1984 Btx hack. A regional television retrospective on the Btx hack thirty years after it happened, revisiting the Hamburg setting and the club members involved. It uses the original 1984 reporting as its source material.
  128. The Hacker Wars. A feature documentary on hacktivists and the prosecutions brought against them, drawing on interviews with the people involved. It covers the legal pressure applied to activists and journalists associated with Anonymous.
  129. Haroon Meer's keynote on why the field is not improving. Haroon Meer's Black Hat Europe keynote asking why, despite growing budgets and larger teams, the industry is still failing at problems it has known about since the nineties. A critical assessment of the security profession by one of its own.
  130. The NSA and FBI push for new backdoors. Coverage of FBI director James Comey's testimony against strong encryption before the Senate Intelligence Committee, alongside the parallel British push for exceptional access. Leading security researchers had published a paper opposing the proposals.
  131. Phil Zimmermann interviewed on Newsnight. BBC Newsnight meets Phil Zimmermann at Mobile World Congress in Barcelona. He recounts the years in which US authorities treated his encryption software as a munitions export and investigated him as an arms dealer.
  132. John Draper tells the Captain Crunch story. Draper gives a conference talk on his own history, from the analog telephone network to the personal computer era. The session was recorded at the Vintage Computing Festival Berlin and archived by media.ccc.de.
  133. Why tech companies may be winning the encryption argument. A news segment on reports that the Obama administration was stepping back from demands for guaranteed access to encrypted data. It places the shift in the context of the Snowden disclosures.
  134. CCC year in review, 32C3. The Chaos Computer Club's annual review session at the 32nd Chaos Communication Congress, covering the club's work over the year, its disclosures and its policy fights. A raw congress recording in German and English.
  135. How the L0pht ended up testifying in Washington. The Washington Post interviews two members of the L0pht about how the collective formed and how it came to tell a Senate committee in May 1998 that it could take down the internet in thirty minutes. A retrospective built on first-hand recollection.
  136. Zero Days, Alex Gibney's Stuxnet documentary. Alex Gibney's feature documentary on Stuxnet, the self-replicating malware that damaged centrifuges at Iran's Natanz enrichment plant and then escaped onto the wider internet. It draws on intelligence-community sources to argue that a new category of weapon had been used without public debate.
  137. Phil Zimmermann on communications security. Phil Zimmermann, creator of PGP and co-founder of Silent Circle, speaks at Google about deploying end-to-end encrypted communications at scale. He covers the engineering and organisational obstacles to making secure messaging ordinary.
  138. Apple's counsel testifies that a back door endangers encryption. Apple general counsel Bruce Sewell tells lawmakers that strong encryption is the best protection for users and that mandated access would undermine it. The testimony came during the dispute over the San Bernardino iPhone.
  139. Updates from the trenches of the second crypto war. A HOPE conference session on the renewed push by law enforcement for surveillance-friendly technology mandates. Speakers review the going dark argument and the legislative proposals attached to it.
  140. The iCloud password reset behind the Apple standoff. A report that the iCloud password on the San Bernardino shooter's phone was reset by a county employee working with the FBI shortly after the device was recovered. The reset closed off a route to the data that would not have required a court order.
  141. The FBI and Apple face off at a congressional hearing. Amy Hess of the FBI's science and technology branch is questioned about relying on outside contractors to unlock seized iPhones. The exchange came as the bureau sought access to a phone used by one of the San Bernardino attackers.
  142. The FBI unlocks the San Bernardino iPhone. The Justice Department announces it has accessed the encrypted iPhone without Apple's assistance, ending the court fight but leaving the legal question open. A Wall Street Journal reporter discusses what the outcome settles and what it does not.
  143. Backdoors, going dark and the encryption dilemma. A long-form conversation between technologists and law enforcement voices on exceptional access to encrypted products. It lays out the competing claims about investigative capability and systemic security.
  144. Diffie and Hellman receive the Turing Award. The ACM presents Whitfield Diffie and Martin Hellman with the A.M. Turing Award for their contributions to modern cryptography. Their 1976 work made it possible for two parties to communicate privately over an insecure channel.
  145. Frederic Jacobs on master keys and mobile privacy. A talk arguing that proposals to build master keys into consumer devices create risks that cannot be contained. Jacobs frames phones as repositories of the most sensitive personal information.
  146. The contest area at DEF CON 24, 2016. Work tables in the contest area at DEF CON 24. The capture-the-flag and hardware-hacking villages are where the culture actually happens, and they look nothing like the stock image of hacking: fluorescent light, folding tables and laptops.
  147. 2600: The Hacker Quarterly. An issue of 2600: The Hacker Quarterly, named for the 2600 Hz tone that opened AT&T's trunks. Founded in 1984 by Eric Corley, it ran continuously through Operation Sundevil, the Mitnick prosecution and the crypto wars, and published the FREE KEVIN campaign.
  148. Hacker, Freaks und Funktionäre. A German television documentary on the rise of the Chaos Computer Club, from West German hacker culture in the 1980s to the club's later role as a public technical authority. It includes interviews with people around the club through its whole history.
  149. Moonlight Maze traced to a modern threat actor. Kaspersky Lab and King's College London researchers describe recovering samples, logs and artefacts from Moonlight Maze, the intrusions that targeted the Pentagon, NASA and others in the late 1990s, and the link they found to a later backdoor. Research that reached back to one of the first documented targeted campaigns.
  150. The original Petya ransomware splash screen. The skull-and-crossbones splash screen of the original Petya ransomware, which encrypted the master file table rather than individual files. NotPetya borrowed its look, which is why the 2017 attack got the wrong name and kept it.
  151. The WannaCry ransom screen lock graphic. The padlock graphic from the WannaCry ransom pop-up of 12 May 2017. WannaCry used EternalBlue, an SMB exploit stolen from the NSA and dumped by the Shadow Brokers, and hit around 200,000 machines in 150 countries including large parts of the NHS. Marcus Hutchins stopped it by registering a hard-coded kill-switch domain for about ten dollars.
  152. Countries hit in the first hours of WannaCry. A map of the countries affected in the first hours of WannaCry, drawn on 14 May 2017. It shows the speed a wormable exploit still had in 2017, seventeen years after ILOVEYOU.
  153. BBC News on WannaCry causing global chaos. BBC News reports that tens of thousands of organisations were hit by WannaCry, which encrypted files and demanded payment of up to three hundred dollars, and that UK hospitals were among the victims, with some diverting patients. The clearest broadcast record of the attack's effect on health services.
  154. Philippine television looks back at WannaCry. An ABS-CBN segment reviewing the WannaCry outbreak, which exploited a vulnerability in older versions of Windows, and what it meant for everyday computer security. A longer-form contemporaneous review rather than breaking coverage.
  155. Nigerian television coverage of the WannaCry attack. Channels Television reports on WannaCry reaching about 150 countries. Coverage from outside the usual Western newsrooms, showing how globally the attack registered.
  156. Journalist interviewed on CBSN during the WannaCry attack. A CBSN interview with reporter Eric Geller recorded on 12 May 2017, the first full day of the WannaCry attack. Analysis given while the scale of the incident was still unclear.
  157. Cliff Stoll on three decades of computer security. Cliff Stoll's keynote at the SANS Cyber Threat Intelligence Summit, returning to the intrusion he tracked and chronicled in The Cuckoo's Egg and setting it against how the field looks decades later. First-hand account from the person who did the original hunt.
  158. Equifax headquarters, Atlanta. Equifax's Atlanta headquarters. In 2017 an unpatched Apache Struts flaw exposed the personal and credit records of about 147 million people, none of whom had ever chosen to be Equifax customers. The settlement reached roughly 700 million dollars and made 'the data broker you cannot opt out of' a mainstream political problem. The subject dates from 2017; the photograph itself is later.
  159. Congressional hearing on the Equifax data breach. The full House Energy and Commerce subcommittee hearing on the Equifax breach, held on 3 October 2017, at which the company's former chief executive was questioned about how the intrusion happened and how consumers were treated afterwards. The complete primary record, over three hours.
  160. ITV News interview after the NotPetya attack. A short ITV News interview recorded in the immediate aftermath of the NotPetya attack of June 2017, which spread rapidly through corporate networks and destroyed data on affected machines. Contemporaneous comment while the incident was still developing.
  161. Maxine Waters questions Equifax at the Financial Services hearing. Ranking member Maxine Waters questions Equifax at the House Financial Services Committee hearing of 5 October 2017, calling the breach and the company's subsequent failures a lapse on a scale not seen before, and noting that affected consumers never chose to do business with Equifax. It frames the credit bureau accountability problem directly.
  162. Jake Davis on why hackers do it. A talk by Jake Davis, formerly of Anonymous and LulzSec, on how loose groups of young people assemble around a shared idea and go on to hack global organisations, and what motivates them. A first-hand account from inside one of the most publicised hacking crews.
  163. The NotPetya ransom screen, 27 June 2017. The message shown to machines hit by NotPetya on 27 June 2017. It demanded a ransom but had no working decryption path: it was a destructive wiper disguised as ransomware, seeded through a Ukrainian tax-software update and spread worldwide. Maersk, Merck and FedEx's TNT each lost hundreds of millions; total damage is estimated at around ten billion dollars.
  164. Exploding the Phone on the toy whistle and the phone network. A narrated excerpt from Phil Lapsley's Exploding the Phone, telling how a phone phreak in the 1950s used luck and ingenuity to get inside the telephone system. It covers the pre-computer origin of the whole discipline.
  165. Parisa Tabriz's Black Hat keynote on fixing security at the root. Parisa Tabriz, then leading Google's Project Zero, delivers the Black Hat USA 2018 keynote arguing that practitioners must tackle root causes and structural change rather than symptoms. A statement of the vulnerability-disclosure philosophy from the team that shaped it.
  166. OpSec talk at 35C3. A German-language talk from the 35th Chaos Communication Congress in Leipzig on operational security for people doing offensive computer work. It is a raw conference recording from the CCC's own media archive.
  167. Martin Hellman on the evolution of public key cryptography. Hellman revisits the path he, Whitfield Diffie and Ralph Merkle took to public key cryptography, and why the idea took so long to surface. The talk was given at the Stanford Computer Systems Colloquium.
  168. Seal of the Cybersecurity and Infrastructure Security Agency. The seal of CISA, the US civilian cyber-defence agency created by statute in November 2018. Its existence is the institutional endpoint of a line that runs from the 1986 Computer Fraud and Abuse Act through CERT/CC to SolarWinds and Log4Shell, where the government's role shifted from prosecuting hackers to defending civilian infrastructure. Public domain as a US federal government work.
  169. DEF CON badges. A collection of DEF CON badges, including the electronic ones. DEF CON has run in Las Vegas since 1993 and its badge, an actual working circuit board with an embedded puzzle, is the conference's signature artifact. Badge hacking is now a genre of its own.
  170. Maersk on the lessons of NotPetya at Black Hat Europe. Maersk CISO Andy Powell's Black Hat Europe briefing on how the shipping group rebuilt after the June 2017 NotPetya attack and what it changed afterwards. A first-hand account from inside one of the worst-hit organisations.
  171. John Draper on the Scene World podcast. A long interview with John Draper covering the blue box, his EasyWriter word processor and his views on security and privacy. It is a first-hand account from one of the central figures of the phreaking scene.
  172. Hacking police speed measurement at DEF CON 27. Bill Swearingen's DEF CON 27 talk on reverse-engineering police speed-measurement devices and building countermeasures. A raw conference recording from the DEF CON archive.
  173. US Air Force cyber airmen at DEF CON 27, 2019. Airmen from the 90th Cyberspace Operations Squadron running a demonstration at DEF CON 27 in August 2019. Twenty years earlier the federal government treated the same conference as a threat; this image documents the absorption of hacker culture into the state. US Air Force work, public domain.
  174. Kernel Panic on the Morris worm. Mashable's documentary episode on the 1988 Morris worm, the self-replicating program that knocked a large share of the early internet offline and led to the first conviction under the Computer Fraud and Abuse Act. Made decades later as a retrospective.
  175. Kevin Mitnick on stage, Perth 2019. Mitnick presenting at an Australian Information Security Association event in Perth in 2019, four years before his death in 2023. A useful late-career frame if the archive wants to close his thread rather than leave him in the 1990s.
  176. How telephone phreaking worked. A detailed walkthrough of in-band signalling on the analogue telephone network and how phreaks used tones to control it. Covers the technical substrate that hacker culture grew out of before computer networks were widespread.
  177. Documentary on the Code Red worm. A history-of-hacking episode on Code Red, the worm that spread through Microsoft IIS web servers in 2001, and on what the response to it changed. Made long after the event.
  178. German documentary on NotPetya. A German-language breakdown of the 2017 NotPetya outbreak, which spread out of Ukraine and caused enormous collateral damage to companies worldwide. Retrospective rather than period coverage.
  179. Demonstration of the ILOVEYOU virus. A run of the ILOVEYOU mail worm in a controlled environment, showing what the script did to files on an infected machine. Useful as a look at the actual artefact rather than a description of it.
  180. Bloomberg buys ransomware on the dark web. A Bloomberg investigations reporter buys ransomware on a dark-web market to show how little skill or money the criminal supply chain now requires. Documents the shift to ransomware sold as a product.
  181. Computerphile on the first internet worm. Dr Julian Onions recalls being on the network in November 1988 when the Morris worm spread, and what cleaning up after it was like. A first-hand recollection recorded decades later.
  182. What went wrong in the SolarWinds compromise. A former CIA information security official explains how the compromise of SolarWinds' Orion build process gave intruders access to thousands of downstream government and corporate networks, and why supply-chain attacks are so hard to prevent. Recorded days after the intrusion became public.
  183. CNBC on SolarWinds and cyber espionage. CNBC's report on the SolarWinds compromise discovered by FireEye in December 2020, which reached more than eighteen thousand of the company's customers, and on the US government's response. Contemporary business-news coverage.
  184. Malicious Life on the Melissa virus. The Malicious Life podcast episode on Melissa, the 1999 macro virus that mailed itself to contacts from infected Outlook address books and forced companies to shut mail servers down. A researched retrospective.
  185. The Colonial Pipeline ransomware note, May 2021. A screenshot of the ransom note left on Colonial Pipeline's systems on 7 May 2021 by the DarkSide affiliate group. The company shut down 5,500 miles of fuel pipeline, causing panic buying across the US east coast, and paid about 4.4 million dollars, most of which the FBI later clawed back. It is the clearest demonstration that ransomware-as-a-service had become a national infrastructure problem.
  186. A Colonial Pipeline right-of-way marker. A pipeline marker photographed weeks after the attack. It is a deliberately unglamorous image: the thing that was shut down by a compromised VPN password with no multi-factor authentication is a buried steel pipe in a field.
  187. Mustafa Al-Bassam on Anonymous and LulzSec. A first-hand interview with Mustafa Al-Bassam, a former member of Anonymous and a founder of LulzSec, on how he got into hacking as a teenager and on the group's 2011 attacks. A participant account rather than a retelling.
  188. Conference talk on ransomware as a service. A recorded conference session on how ransomware became a rented service with affiliates, negotiation and support, and what that means for detection and response. A practitioner talk rather than an explainer.
  189. CNBC on the group behind the Colonial Pipeline attack. TrustedSec's David Kennedy on CNBC on 12 May 2021, days after ransomware forced Colonial Pipeline to halt fuel deliveries on the US East Coast, discussing the criminal group and how such operations work. Period broadcast coverage.
  190. The Hanover hackers and the KGB. An account of the group of young hackers in Hannover who broke into networked systems and sold material to the Soviet KGB, and of how the astronomer Clifford Stoll picked up their trail. The video lists its sources publicly.
  191. Jen Easterly, CISA director. Jen Easterly's official portrait, taken shortly before she was sworn in as CISA director in July 2021. She took the job between Colonial Pipeline in May and Log4Shell in December, and ran the federal response to both. Public domain as a US federal government work.
  192. The Koobface botnet and the hunt for a hacker. A documentary episode built around the Koobface botnet, which spread through social networks from 2008, alongside the manhunt for Kevin Mitnick. Traces how malware moved onto social platforms.
  193. Origins of the computer virus. A documentary on where self-replicating code came from, from the Darwin programming game and early theoretical work through Creeper on ARPANET. Covers the pre-history that the later virus era grew out of.
  194. Cypherpunks Write Code. A four-part documentary on the cypherpunk movement, covering the fight over cryptography export controls and the campaign to make strong encryption publicly available. It draws on interviews with participants from the 1990s mailing list.
  195. Apache Log4j. The Apache Log4j logo. Log4Shell (CVE-2021-44228), disclosed 9 December 2021, let an attacker run arbitrary code on any Java service that logged a hostile string, and Log4j was inside a very large share of the world's enterprise software. It is the defining software-supply-chain incident: a single unpaid volunteer library at the base of a global stack.
  196. First look at the Log4Shell vulnerability. A walkthrough recorded in the first days after CVE-2021-44228 became public, showing the flaw being triggered through Minecraft chat and explaining why an ordinary logging library exposed so much of the internet.
  197. How Log4Shell came to exist. An analysis of the Log4j flaw that goes back through the library's feature history and the earlier issues that made the JNDI lookup path possible, rather than only demonstrating the exploit. Covers how a decade-old design decision produced the disclosure.
  198. United States v. Morris, the case brief. A summary of the 1991 appellate decision in United States v. Morris, the first conviction under the Computer Fraud and Abuse Act to be tested on appeal, and of what the court held about intent under the statute. The legal aftermath of the 1988 worm.
  199. Clifford Stoll and the Berkeley intrusion. A long-form retelling of how an unemployed astronomer working in university IT followed a small accounting discrepancy into an international espionage investigation. It covers the state of computer security in 1986.
  200. Google on Operation Aurora. The opening episode of Google's own documentary series on the 2009 intrusion into its network, in which attackers went after the accounts of human rights activists. Google's account of an attack that changed how the company and the industry talked about state-linked intrusions.
  201. Documentary on Titan Rain. A documentary on the Titan Rain intrusions against US defence networks in the mid-2000s, and on Shawn Carpenter, the analyst who followed the intruders and lost his job for it. Covers one of the first publicly discussed campaigns of sustained network espionage.
  202. Tracking the KGB hackers over 75 cents. A French-language documentary on Clifford Stoll's pursuit of an intruder in Lawrence Berkeley's systems during the Cold War, which ended in a West German espionage case. It reconstructs the monitoring work he improvised to follow the connection.
  203. How phreaking really worked, from a telephone museum. A demonstration at a working telephone switching museum of the signalling that blue boxes exploited, using real equipment rather than diagrams. Shows in-band supervision and multi-frequency tones doing what phreaks used them for.
  204. Detecting the MOVEit exploitation. Threat research on CVE-2023-34362 in MOVEit Transfer, showing the observable activity left behind by the mass exploitation campaign that led to data theft at large numbers of organisations. Defensive detection work on an unfolding incident.
  205. A visitor's tour of the 37th Chaos Communication Congress. Footage and impressions from 37C3, the Chaos Computer Club's annual congress in Hamburg, filmed by an American attendee for a US security audience. It is a useful outsider's record of the CCC's assemblies, art installations and talk culture, the European counterweight to DEF CON.
  206. The MOVEit mass exploitation. A breakdown of the MOVEit Transfer zero-day and the scale of the resulting data theft across corporate and government users of the file transfer product. Covers why a single managed file transfer tool exposed so many downstream organisations.
  207. Inside the ransomware economy on the dark web. A tour of the leak sites, forums and marketplaces that make up the ransomware criminal economy, showing how victims are named and data auctioned. Research into the infrastructure of extortion rather than a single incident.
  208. Old malware and the Malware Museum. A look at DOS-era viruses through the Internet Archive's Malware Museum, where defanged copies run in the browser, and at how visibly performative early malware was compared with what came later.
  209. 37C3, Hamburg, December 2023. Setup day before the 37th Chaos Communication Congress in Hamburg. Forty years on from the CCC's founding, the congress runs at the scale of a small city, which is itself the story: what was a subculture is now infrastructure.
  210. Newsthink profile of Kevin Mitnick's social engineering. A researched profile of Kevin Mitnick, the hacker whose intrusions into telecom and technology companies made him the most publicised computer-crime defendant of the 1990s. The video's focus is social engineering: persuading people, rather than breaking code, was his primary technique.
  211. Privacy International on the politics of the crypto wars. A long discussion between Privacy International staff on the history of encryption policy, led by a colleague who has worked on the debate since the 1990s. It covers the export-control fights, the recurring push for lawful access, and why the same arguments keep returning.
  212. PBS NewsHour on the Change Healthcare attack's effect on hospitals. Stephanie Sy interviews Washington Post reporter Dan Diamond about the February 2024 cyberattack on Change Healthcare and the cash-flow crisis it caused for hospitals, doctors and patients. Contemporaneous national coverage of one of the most disruptive incidents ever to hit US healthcare.
  213. Local news report on Change Healthcare's outage hitting mental health providers. A KOIN 6 report from the weeks after the February 2024 Change Healthcare attack, following mental health providers in Oregon and California who could not bill or get paid while the claims system was down. It shows the second-order damage of an attack on shared healthcare infrastructure.
  214. Cult of the Dead Cow panel on forty years of hacker history at DEF CON 32. Members of the Cult of the Dead Cow and their contemporaries look back over four decades, from Texas bulletin-board culture in the mid-1980s through the group's later releases and public campaigns. A first-hand oral history from people who were inside the scene.
  215. Reticulum networking talk at 38C3. A Chaos Communication Congress talk presenting Reticulum, a cryptography-based networking stack designed to keep working over high-latency, low-bandwidth and adversarial links using commodity radio hardware. It is a working example of the CCC's long-running interest in infrastructure that cannot easily be switched off.
  216. Fireship on the CrowdStrike update that crashed Windows fleets. A same-day breakdown of the 19 July 2024 CrowdStrike Falcon content update that sent millions of Windows machines into boot loops, grounding flights and halting hospitals and broadcasters. It is a rare case of a security product itself becoming the outage.
  217. Crumb's investigation into the LockBit ransomware operation. A long-form investigation into LockBit, the ransomware-as-a-service group whose affiliates hit Royal Mail and hundreds of other organisations, and into the effort to identify the people running it. It shows ransomware operating as a franchised business rather than a lone-hacker crime.
  218. A retired Windows engineer explains Stuxnet. Dave Plummer walks through the technical construction of Stuxnet: the chained zero-days, the stolen code-signing certificates, and the payload that manipulated centrifuge frequency converters while replaying normal readings to operators. Told from the perspective of an engineer who worked on the operating system it abused.
  219. Cybernews on the 2007 attacks that knocked Estonia offline. A detailed account of the three weeks in April and May 2007 when sustained denial-of-service traffic took down Estonian ministries, banks and newspapers. The episode covers how a small, heavily digitised state responded, and why the incident pushed NATO to open its cyber defence centre in Tallinn.
  220. Paras Jha and the Mirai botnet. The story of Mirai, the botnet built from IoT devices with default credentials that was used against Krebs on Security, the French host OVH and the DNS provider Dyn in 2016. Its author, Paras Jha, had started out attacking Minecraft servers; the source code was published before the largest attacks.
  221. Cybernews on NotPetya. An account of the 27 June 2017 NotPetya outbreak, which spread from a compromised update to the Ukrainian accounting package M.E.Doc and destroyed data across Ukraine and then worldwide. Presented as ransomware, it had no working recovery path, and the damage ran into billions of dollars.
  222. IBM X-Force threat intelligence briefing for 2025. Jeff Crume walks through IBM's annual X-Force Threat Intelligence Index, covering credential theft, dark-web trade and the early use of AI by attackers. Annual industry indexes like this are how the defensive side measures what changed year to year.
  223. Jennifer Granick's Black Hat keynote on threat modeling and constitutional law. Granick, a civil-liberties lawyer, argues that constitutional doctrine models threats badly: it trusts the wrong insiders, overreacts to outsiders, and adapts slowly. A keynote about the legal architecture that surrounds surveillance and computer crime rather than about the technology.
  224. Citizen Lab's Black Hat keynote on twenty years of counter-intelligence research. A keynote drawing on two decades of Citizen Lab investigations at the University of Toronto into state cyber-espionage and the mercenary spyware industry that sells to governments. The lab's work is the main public evidence base for spyware found on the phones of journalists and activists.
  225. Microsoft's security keynote on agentic AI at RSAC 2025. Vasu Jakkal's RSA Conference keynote arguing that autonomous AI agents will change both attack and defence, and setting out how Microsoft expects security teams to work alongside them. A snapshot of how the largest vendors framed the AI question in 2025.
  226. CBS Mornings on Anthropic's report of an AI-run espionage campaign. CBS covers Anthropic's disclosure that a group it assessed as Chinese state-sponsored used its AI tools to run an espionage campaign against technology firms, financial institutions and government agencies with little human involvement. Former CISA director Chris Krebs discusses what it means for defenders.
  227. Mikko Hypponen's Black Hat keynote on three decades of malware research. Hypponen's 2025 Black Hat USA keynote, looking back over a career that began in 1991 with floppy-disk viruses and now takes in nation-state operations and AI. A first-hand account from one of the few researchers who has been present for the whole arc.
  228. CNBC on security stocks after the first reported AI-orchestrated attack. CNBC reports on the market reaction after Anthropic published its account of what it described as the first largely AI-orchestrated cyber-espionage campaign. The segment captures the moment the industry began pricing in autonomous attack tooling.
  229. SecTor keynote on identity in an agentic AI world. A SecTor 2025 keynote in Toronto arguing that corporate identity management, already unsolved, becomes far harder once autonomous AI agents each need their own identity and attributes. It sets out the problem rather than claiming a solution.
  230. NetworkChuck's first DEF CON. A first-timer's walk through DEF CON 33 in Las Vegas: the villages, lockpicking, car hacking, and encounters with people behind well-known security tools. Useful as a record of what the conference actually looks like on the floor rather than on stage.
  231. Cybernews on the SolarWinds supply-chain compromise. How a backdoor inserted into SolarWinds' Orion network-management updates reached thousands of customers, including US federal agencies, before the intrusion was found in December 2020. The episode explains why compromising a trusted software vendor is more efficient than attacking each target.
  232. Cybernews on WannaCry. The 12 May 2017 WannaCry outbreak spread through a Windows SMB flaw and reached organisations in around 150 countries, including hospitals in the UK's National Health Service. The episode covers the domain registration that acted as a kill switch and stopped the spread.
  233. Cybernews on the Colonial Pipeline ransomware attack. On 7 May 2021 ransomware hit the business network of Colonial Pipeline, the largest refined-fuel pipeline in the United States, and the company shut the pipeline down. The episode covers the fuel shortages and panic buying that followed and the partial recovery of the ransom payment.
  234. SQL Slammer, the 376-byte worm. In January 2003 a worm exploiting a Microsoft SQL Server buffer overflow spread worldwide in minutes using single UDP packets, saturating networks rather than damaging data. Its speed made it the textbook case for how fast a small payload can propagate.
  235. Titan Rain and the discovery of long-running network espionage. Titan Rain was the US government codename for a series of coordinated intrusions into defence and government networks detected in the early 2000s. The episode covers how investigators came to see persistent, patient network espionage as a standing condition rather than isolated break-ins.
  236. Cybernews on AI-assisted hacking. An examination of how large language models are being used offensively, built around the reported case in which a single operator used an AI system to attack seventeen organisations in under a month. It separates what these tools currently automate from what still needs a human.
  237. The CISO Signal on the Change Healthcare breach. A long episode on the February 2024 attack that took down Change Healthcare, the clearing house through which a large share of US medical claims are processed. It explains why an outage in unseen back-office plumbing stopped prescriptions and payments across the country.
  238. ABS-CBN revisits the ILOVEYOU virus. A Philippine broadcast episode on the ILOVEYOU worm of May 2000, which spread as an email attachment named LOVE-LETTER-FOR-YOU.txt.vbs and overwrote files as it mailed itself onward. It is told from the country where the code was written, where prosecutors found no law under which to charge anyone.
  239. Black Hat Asia keynote on autonomous offensive systems. A keynote tracing the move from prompt-injection tricks to systems that can carry out meaningful offensive security work without human intervention, and the advances over the previous three years that made it possible. Delivered as the question stopped being hypothetical.
  240. Black Hat's president on how the conference is changing. An interview recorded at Black Hat 2026 with Suzy Pallett, president of Black Hat, on how the event's programming has shifted as AI reshapes the threat landscape. A view of the conference as an institution from the person running it.
  241. Cisco's RSAC keynote on securing an agentic workforce. Jeetu Patel's RSA Conference keynote on what happens when AI agents are deployed at machine speed inside companies: protecting agents from the world, protecting the world from agents, and responding at the same speed. A record of how the industry framed the agentic problem in 2026.
  242. Fern's account of Kevin Mitnick. A carefully sourced telling of the Mitnick case, drawing on the published books about it, covering the intrusions, the manhunt, the years he spent in custody before trial and the gap between the media portrayal and the record. One of the better treatments of how the story was inflated as it was told.
  243. Hector Monsegur on LulzSec and what came after. A long interview with Hector Monsegur, who as Sabu was part of LulzSec before being arrested and cooperating with the FBI, and who now works as a security researcher. A first-hand account from inside one of the most consequential hacktivist crews of the early 2010s.
  244. Operation Cronos and the takedown of LockBit. How an international law-enforcement operation seized LockBit's infrastructure in February 2024 and turned the gang's own leak site into a countdown of police disclosures. The episode also covers how LockBit ran as a business, with affiliates, bug bounties and a leaderboard.

Full text archive: /loreline-text/cybersecurity.md

CYBERSECURITY
MOMENTS0000
VIEWS0000
LIKES0000
TIME0000
Search moments...
The Morris Worm source code on a floppy disk, museum exhibit | Loreline