Unclassified // Open source

Dated stories & sourced events

Every entry carries the date it entered the public record, what happened, why it matters for United States cyber posture, and the specific open-source material behind it. 31 events on file.

  1. Policy & strategy

    Emergency Directive 26-01 after a nation-state intrusion at F5

    F5 disclosed long-term nation-state access to systems holding BIG-IP source code and undisclosed vulnerability information, and CISA issued Emergency Directive 26-01 the same day. Remove appliance management interfaces from the public internet and patch on the directive timeline.

    Undisclosed nation-state actorF5
  2. Criminal & non-state

    Oracle E-Business Suite zero-day drives a mass extortion campaign

    Google Threat Intelligence Group and Mandiant documented exploitation of an Oracle E-Business Suite zero-day for mass data theft followed by extortion of dozens of organizations. Inventory internet-reachable enterprise resource planning systems and alert on unusual outbound data volume.

    CL0PFIN11
  3. Policy & strategy

    Joint advisory AA25-239A describes a global Chinese espionage system

    CISA, the National Security Agency, the Federal Bureau of Investigation and international partners published a joint advisory on People's Republic of China actors compromising backbone routers worldwide to feed an espionage system. Use the advisory's router hardening and configuration comparison guidance as a baseline task, not a reference document.

    Salt TyphoonPeople's Republic of China state actors
  4. State intrusions

    On-premises SharePoint exploitation attributed to Chinese state actors

    Microsoft attributed active exploitation of on-premises SharePoint vulnerabilities to three China-linked clusters, with machine key theft enabling persistence after patching. Rotate SharePoint machine keys, because the update alone does not evict the actor.

    Linen TyphoonViolet TyphoonStorm-2603
  5. Law enforcement

    Justice Department charges twelve Chinese contract hackers and police officers

    Unsealed indictments named contract operators and Chinese law enforcement officers running intrusions for hire against agencies, dissidents and news organizations. Attribution now reaches the commercial intermediaries as well as the state customer.

    i-SoonMinistry of Public SecurityAPT27
  6. State intrusions

    Recorded Future finds Salt Typhoon still exploiting Cisco devices at telecom providers

    Insikt Group observed continued exploitation of known Cisco IOS XE vulnerabilities against telecommunications providers between December 2024 and January 2025, after sanctions. Patch and inventory network edge devices, because designation did not slow the operation.

    RedMikeSalt Typhoon
  7. Policy & strategy

    Treasury sanctions a Sichuan firm over Salt Typhoon and the Treasury network breach

    The Office of Foreign Assets Control designated a Chinese technology company tied to the telecommunications campaign and an actor connected to the intrusion into Treasury's own systems. Sanctions now arrive before technical remediation is finished, not after.

    Sichuan Juxinhe Network TechnologySalt Typhoon
  8. State intrusions

    Salt Typhoon intrusions reach United States telecommunications carriers

    Chinese state operators sat inside major carrier networks with access to call records and lawful intercept systems. Federal agencies responded by recommending encrypted messaging for sensitive communications, which is a striking admission about network trust.

    Salt Typhoon
  9. State intrusions

    FBI and CISA confirm the Salt Typhoon compromise of United States telecom carriers

    The two agencies publicly confirmed People's Republic of China access inside multiple telecommunications carriers, including call records and lawful intercept systems. Treat carrier infrastructure as a national intelligence target, not a commercial one.

    Salt TyphoonMinistry of State Security
  10. Law enforcement

    Court-authorized takedown of the Raptor Train botnet

    The Federal Bureau of Investigation disrupted a botnet of roughly 260,000 consumer devices used by Chinese state operators as attack infrastructure. Court-authorized remote remediation is now a recurring instrument against state proxies.

    Flax Typhoon
  11. Criminal & non-state

    Change Healthcare ransomware freezes national claims processing

    Ransomware against a single clearinghouse stopped prescription and provider payments across the country for weeks. Concentration in health care infrastructure is now treated as a systemic risk.

    ALPHV/BlackCat
  12. Law enforcement

    Operation Cronos dismantles LockBit infrastructure

    An international operation seized LockBit servers, took the leak site and used it to publish information about the group. Disruption of criminal brands, not only arrests, is now standard practice.

    LockBitInternational law enforcement
  13. Cyber operations

    Iran-linked operators deface water utility controllers in Pennsylvania

    Operators tied to Iran's Islamic Revolutionary Guard Corps exploited default credentials on industrial controllers at a municipal water authority. Small utilities with minimal staff are the softest target set in United States critical infrastructure.

    CyberAv3ngers
  14. Criminal & non-state

    MOVEit mass exploitation turns one file transfer flaw into thousands of breaches

    A criminal group exploited a zero-day in a managed file transfer product and stole data from thousands of organizations, including federal agencies. Third-party data processors are now a primary breach vector.

    Cl0p
  15. State intrusions

    Volt Typhoon surfaces in Guam telecommunications networks

    Microsoft and allied agencies described Chinese state operators living off the land inside United States communications infrastructure with no espionage payload. The activity reads as preparation for disruption during a Pacific conflict, not intelligence collection.

    Volt Typhoon
  16. Policy & strategy

    National Cybersecurity Strategy shifts the burden to capable actors

    The strategy argued that security responsibility should sit with software makers and large service providers rather than individuals and small operators. It also endorsed disruption operations as routine practice.

    Office of the National Cyber Director
  17. Policy & strategy

    Cyber Incident Reporting for Critical Infrastructure Act becomes law

    Critical infrastructure entities must report significant cyber incidents within 72 hours and ransom payments within 24 hours once the rule takes effect. It converts voluntary information sharing into a legal duty.

    CongressCISA
  18. Cyber operations

    Viasat modem wiper accompanies the invasion of Ukraine

    A wiper deployed against satellite modems disrupted Ukrainian military communications at the hour of the invasion and knocked out service across Europe. It is the clearest public case of a cyber operation timed to a conventional military opening move.

    Russian military intelligence
  19. State intrusions

    Log4Shell exposes a single library at the base of the internet

    A trivially exploitable flaw in a ubiquitous Java logging library forced emergency response across nearly every large organization. It is the reference case for dependency risk and software inventory.

    Multiple state and criminal actors
  20. Policy & strategy

    Executive Order 14028 sets federal cyber baselines

    The order mandated zero trust adoption, endpoint detection deployment, logging standards and software supply chain security across federal agencies. Read it as the operating manual behind most federal cyber requirements now in force.

    White House
  21. Criminal & non-state

    Colonial Pipeline ransomware halts fuel delivery on the East Coast

    A criminal ransomware intrusion into business systems led the operator to shut a major fuel pipeline, producing shortages across several states. It moved ransomware from a corporate cost problem to a national security problem.

    DarkSide
  22. State intrusions

    ProxyLogon mass exploitation hits tens of thousands of Exchange servers

    Four chained zero-day vulnerabilities in on-premises Exchange were exploited at scale before patches existed. Emergency patching timelines for the federal enterprise date from this event.

    Hafnium
  23. State intrusions

    SolarWinds supply-chain compromise reaches nine federal agencies

    Operators tied to Russia's foreign intelligence service trojanized a widely deployed network management update and used it to reach government and technology victims. Software supply chains became a first-order national security concern.

    APT29
  24. Policy & strategy

    Cybersecurity and Infrastructure Security Agency established

    Legislation converted a departmental directorate into a standalone federal agency for civilian cyber defense. Every advisory, binding directive and sector partnership referenced on this platform flows from that authority.

    Department of Homeland Security
  25. Cyber operations

    NotPetya wiper causes the costliest cyber damage on record

    A destructive wiper disguised as ransomware spread from Ukrainian tax software into multinational networks and caused damage widely estimated above ten billion dollars. It established that collateral effects of a state operation land on private companies.

    Sandworm
  26. Criminal & non-state

    WannaCry spreads worldwide using a leaked exploit

    Ransomware built on a leaked exploit disabled hospital systems across the United Kingdom and hit organizations in more than 150 countries in a day. It is the clearest demonstration that unpatched internet-exposed services scale an attack globally.

    Lazarus Group
  27. Policy & strategy

    United States government publicly attributes election interference to Russia

    A joint statement from the Department of Homeland Security and the Office of the Director of National Intelligence named Russia as directing hacks of political organizations. Public attribution by the executive branch became a standing policy tool.

    APT28APT29
  28. Cyber operations

    Ukraine power grid attack causes the first confirmed cyber blackout

    Operators remotely opened breakers at three Ukrainian distribution companies and cut power to roughly 225,000 customers. It is the baseline scenario every United States grid exercise has modeled since.

    Sandworm
  29. State intrusions

    Office of Personnel Management breach exposes clearance files

    The theft of background investigation records on more than 21 million people turned a federal information technology failure into a counterintelligence emergency. Treat it as the reference case for consequences that cannot be remediated by a password reset.

    China-nexus operators
  30. State intrusions

    APT1 report puts a unit number on Chinese cyber espionage

    Mandiant publicly tied years of intellectual property theft to a specific People's Liberation Army unit and a specific building in Shanghai. Attribution became a usable instrument of policy from this point forward.

    PLA Unit 61398
  31. Cyber operations

    Stuxnet discovered, proving code can break machines

    The public discovery of Stuxnet established that software can cause physical destruction in an industrial plant. Read it as the founding case of modern cyber operations doctrine.

    Undisclosed state operators