June 17, 2010

Stuxnet worm discovered targeting industrial systems

Belarusian security firm VirusBlokAda identified the Stuxnet wormSelf-replicating malware that spreads across networks without needing a host file. on June 17, 2010 — malwareMalicious software — viruses, worms, trojans, and ransomware designed to harm systems or steal data. that exploited multiple Windows zero-days to sabotage Iranian nuclear centrifuges via Siemens PLCs.

What it was for

Stuxnet was the first known cyberweapon to cause physical destruction — USBUniversal Serial Bus — a standard connector and protocol for peripherals and devices. propagation, stolen code-signing certificates, and PLC ladder-logic manipulation in one package. It launched the era of nation-state APT research, ICS security teams, and air-gapped network paranoia. Developers securing SCADA and IoTInternet of Things — networked sensors and devices embedded in appliances, factories, and cities. still reference Stuxnet as the proof point.

Why it's here

Stuxnet was the first malwareMalicious software — viruses, worms, trojans, and ransomware designed to harm systems or steal data. proven to cross from ITInformation technology — the use of computers, networks, and software in organizations. networks into physical plant damage.

Why it mattered

It created the ICS/OT security industry and nation-state cyber doctrine.

What it solved

Nothing for defenders initially — it showed industrial control systems were as vulnerable as office PCs.

Related