Defending the Net

The other half of the story: CERT and later CISA, the firewall, the disclosure fights, and the flaws that made everyone look at their dependencies — Heartbleed, Shellshock, Log4Shell. It includes the people who testified, published and patched, from L0pht's 1998 Senate appearance onward.

Part of Cybersecurity

32 moments in this segment.

  1. A Cray-1 supercomputer. A Cray-1, the machine that defined what 'the big computer' looked like to the public in the WarGames era. WarGames (1983) put the idea of a teenager dialling into a military system in front of a mass audience, and led directly to congressional hearings. No frame of the film itself is freely licensed. The subject dates from 1983; the photograph itself is later.
  2. Boxed Netscape Navigator, Computer History Museum. Retail-boxed Netscape Navigator in the Computer History Museum collection. Netscape shipped SSL in 1994-95, putting encryption into an ordinary consumer product for the first time; SSL 3.0 in 1996 is the direct ancestor of TLS and of the padlock icon. Export rules meant the international build was deliberately crippled to 40-bit keys. The subject dates from 1995; the photograph itself is later.
  3. A rack-mounted Cisco PIX 515 firewall. A Cisco PIX, the appliance that made the dedicated network firewall a normal thing to buy rather than a research idea. Cisco acquired the PIX in 1995 and it dominated the perimeter through the late 1990s, the years when 'security' still largely meant 'a hard shell around a soft network'. The subject dates from 1996; the photograph itself is later.
  4. Netscape Navigator 2.02. A screenshot of Netscape Navigator 2.02, the browser generation in which SSL became routine. Period software screenshots are scarce under free licences, so this CC0 capture is worth keeping even though it was taken in 2015 on Windows XP. The subject dates from 1996; the photograph itself is later.
  5. Michael Lynn presenting the Cisco IOS flaw, Black Hat 2005. Michael Lynn on stage at Black Hat on 27 July 2005, having resigned from ISS that morning so he could demonstrate remote code execution on Cisco IOS routers. Cisco had the printed slides torn out of every conference programme and sued; the talk became the defining case in the disclosure-versus-suppression fight.
  6. Bruce Schneier at CFP 2007. Bruce Schneier, author of Applied Cryptography and the person who did most to move the public conversation from 'ciphers' to 'systems and incentives'. His phrase 'security theatre' entered general use after 2001. Photographed on a net-freedom panel in 2007.
  7. Eric Corley (Emmanuel Goldstein) at Chaos Communication Camp 2011. Eric Corley, who publishes 2600 under the name Emmanuel Goldstein, speaking at Chaos Communication Camp in 2011. He was the defendant in Universal v. Reimerdes, the first major DMCA case, over publishing the DeCSS DVD descrambler.
  8. RSA Conference 2012 keynote on client-to-cloud security. Intel's Pranav Mehta delivers an RSA Conference 2012 keynote on securing systems from the client through to the cloud. A period artifact of how the security industry framed its priorities as workloads moved off the endpoint.
  9. Black Hat Briefings at Caesars Palace, 2012. The 15th Black Hat Briefings at Caesars Palace in Las Vegas, 2012. Black Hat is the commercial half of the Las Vegas security week that DEF CON began: same city, same researchers, corporate budgets.
  10. The Heartbleed logo. designed at Codenomicon and released CC0 alongside the April 2014 disclosure of CVE-2014-0160. A missing bounds check in OpenSSL's heartbeat extension let anyone read 64KB of server memory at a time, including private keys. Heartbleed is where branded vulnerabilities began, and the logo is itself the historical artifact.
  11. Running the Heartbleed exploit code, on Computerphile. Dr Steven Bagley walks through the actual code that exploits the Heartbleed bug and runs it, showing what memory comes back. One of the clearest contemporaneous technical explanations of the flaw.
  12. Heartbleed causes, implementation and timeline, at NISC 2014. A conference presentation delivered on 14 May 2014 covering how the Heartbleed bug came to be written, how the flawed implementation worked, and the timeline of its discovery and disclosure. Longer and more technical than the news-cycle explainers.
  13. Dan Geer's Black Hat keynote on cybersecurity as realpolitik. Dan Geer's keynote at Black Hat USA 2014, arguing that security is a matter of power and policy rather than wishes for safety or order, and proposing a set of concrete policy positions. One of the most cited conference talks in the field.
  14. The Shellshock bug explained. Tom Scott explains the Shellshock bug in Bash, a flaw in how the shell handled environment variables that left large numbers of internet-facing systems exploitable. Recorded within days of the vulnerability becoming public.
  15. Haroon Meer's keynote on why the field is not improving. Haroon Meer's Black Hat Europe keynote asking why, despite growing budgets and larger teams, the industry is still failing at problems it has known about since the nineties. A critical assessment of the security profession by one of its own.
  16. Parisa Tabriz's Black Hat keynote on fixing security at the root. Parisa Tabriz, then leading Google's Project Zero, delivers the Black Hat USA 2018 keynote arguing that practitioners must tackle root causes and structural change rather than symptoms. A statement of the vulnerability-disclosure philosophy from the team that shaped it.
  17. Seal of the Cybersecurity and Infrastructure Security Agency. The seal of CISA, the US civilian cyber-defence agency created by statute in November 2018. Its existence is the institutional endpoint of a line that runs from the 1986 Computer Fraud and Abuse Act through CERT/CC to SolarWinds and Log4Shell, where the government's role shifted from prosecuting hackers to defending civilian infrastructure. Public domain as a US federal government work.
  18. Jen Easterly, CISA director. Jen Easterly's official portrait, taken shortly before she was sworn in as CISA director in July 2021. She took the job between Colonial Pipeline in May and Log4Shell in December, and ran the federal response to both. Public domain as a US federal government work.
  19. Apache Log4j. The Apache Log4j logo. Log4Shell (CVE-2021-44228), disclosed 9 December 2021, let an attacker run arbitrary code on any Java service that logged a hostile string, and Log4j was inside a very large share of the world's enterprise software. It is the defining software-supply-chain incident: a single unpaid volunteer library at the base of a global stack.
  20. First look at the Log4Shell vulnerability. A walkthrough recorded in the first days after CVE-2021-44228 became public, showing the flaw being triggered through Minecraft chat and explaining why an ordinary logging library exposed so much of the internet.
  21. How Log4Shell came to exist. An analysis of the Log4j flaw that goes back through the library's feature history and the earlier issues that made the JNDI lookup path possible, rather than only demonstrating the exploit. Covers how a decade-old design decision produced the disclosure.
  22. Detecting the MOVEit exploitation. Threat research on CVE-2023-34362 in MOVEit Transfer, showing the observable activity left behind by the mass exploitation campaign that led to data theft at large numbers of organisations. Defensive detection work on an unfolding incident.
  23. Fireship on the CrowdStrike update that crashed Windows fleets. A same-day breakdown of the 19 July 2024 CrowdStrike Falcon content update that sent millions of Windows machines into boot loops, grounding flights and halting hospitals and broadcasters. It is a rare case of a security product itself becoming the outage.
  24. IBM X-Force threat intelligence briefing for 2025. Jeff Crume walks through IBM's annual X-Force Threat Intelligence Index, covering credential theft, dark-web trade and the early use of AI by attackers. Annual industry indexes like this are how the defensive side measures what changed year to year.
  25. Microsoft's security keynote on agentic AI at RSAC 2025. Vasu Jakkal's RSA Conference keynote arguing that autonomous AI agents will change both attack and defence, and setting out how Microsoft expects security teams to work alongside them. A snapshot of how the largest vendors framed the AI question in 2025.
  26. Mikko Hypponen's Black Hat keynote on three decades of malware research. Hypponen's 2025 Black Hat USA keynote, looking back over a career that began in 1991 with floppy-disk viruses and now takes in nation-state operations and AI. A first-hand account from one of the few researchers who has been present for the whole arc.
  27. CNBC on security stocks after the first reported AI-orchestrated attack. CNBC reports on the market reaction after Anthropic published its account of what it described as the first largely AI-orchestrated cyber-espionage campaign. The segment captures the moment the industry began pricing in autonomous attack tooling.
  28. SecTor keynote on identity in an agentic AI world. A SecTor 2025 keynote in Toronto arguing that corporate identity management, already unsolved, becomes far harder once autonomous AI agents each need their own identity and attributes. It sets out the problem rather than claiming a solution.
  29. Cybernews on AI-assisted hacking. An examination of how large language models are being used offensively, built around the reported case in which a single operator used an AI system to attack seventeen organisations in under a month. It separates what these tools currently automate from what still needs a human.
  30. Black Hat Asia keynote on autonomous offensive systems. A keynote tracing the move from prompt-injection tricks to systems that can carry out meaningful offensive security work without human intervention, and the advances over the previous three years that made it possible. Delivered as the question stopped being hypothetical.
  31. Black Hat's president on how the conference is changing. An interview recorded at Black Hat 2026 with Suzy Pallett, president of Black Hat, on how the event's programming has shifted as AI reshapes the threat landscape. A view of the conference as an institution from the person running it.
  32. Cisco's RSAC keynote on securing an agentic workforce. Jeetu Patel's RSA Conference keynote on what happens when AI agents are deployed at machine speed inside companies: protecting agents from the world, protecting the world from agents, and responding at the same speed. A record of how the industry framed the agentic problem in 2026.
DETO3DEU
MOMENTS0000
VIEWS0000
LIKES0000
TIME0000
Search moments...