The file went out at about two in the afternoon, London time, on Wednesday 21 April 2010 — nine in the morning in New York, by McAfee's own account of it. DAT 5958 was a routine set of virus definitions for McAfee's VirusScan Enterprise, and it identified svchost.exe as the W32/Wecorl.a virus. Svchost.exe is not a virus; it is the process Windows uses to run its own services. The scanner quarantined it. Computers running Windows XP Service Pack 3 lost their networks and began restarting in loops, and some blue-screened. The loop was the trap: a machine with no network cannot be sent a correction, so each one had to be repaired by somebody sitting in front of it — the fix, as the SANS Internet Storm Center put it that afternoon, "has to be applied locally at the workstation".

What that meant showed first in hospitals. Nancy Jean, a spokeswoman for the Lifespan group in Rhode Island, said about a third of the state's hospitals had stopped treating patients without trauma in their emergency rooms and had postponed some elective surgery; gunshot wounds and road accidents were still admitted. Kentucky State Police were told to switch off the computers in their patrol cars. The National Science Foundation lost machines at its Arlington headquarters; at the University of Michigan eight thousand of the twenty-five thousand computers in the health system and medical school went down, and at Upstate University Hospital in Syracuse 2,500 of 6,000. Intel was hit; so, in Australia, were the Commonwealth Bank, a number of Coles stores and — by one Australian account — a quarter of Virgin Mobile's PCs. An emergency response centre in Iowa was in the middle of a disaster recovery exercise when its 911 centre went offline.

McAfee pulled the file from its download servers within hours and shipped an emergency replacement, DAT 5959, together with an EXTRA.DAT that could be carried to a stricken machine and applied in safe mode; US-CERT issued its own alert the same day. The company's first line, from its spokesman Joris Evers, allowed "moderate to significant performance issues" and said the company was "not aware of significant impact on consumer customers". The apology came late on Thursday 22 April, on the company blog, from Barry McPherson, executive vice-president for support and customer service. He explained how it had happened — "We recently made a change to our QA environment that resulted in a faulty DAT making its way out of our test environment and onto customer systems" — and finished: "Mistakes happen. No excuses."

How many machines were affected was never settled. McAfee said less than half of one per cent of its enterprise accounts globally; individual customers counted thousands of machines each. Its chief executive, David DeWalt, said nothing; his last blog entry, Computerworld noted, was dated 15 April. On 26 April the company told home and home-office customers that "if you have already incurred costs to repair your PC as a result of this issue, we're committed to reimbursing reasonable expenses", without defining reasonable. The general lesson was the harder one: an anti-virus update is privileged code, shipped to millions of machines at once and at speed, with nothing between the vendor and the endpoint. The same sentence was written about a different company in July 2024; McAfee itself agreed that August to be bought by Intel.

Also that month · 5–13 April

The Post-Mortem Apache Published

On 5 April 2010 someone opened an issue on the Apache Software Foundation's JIRA tracker — INFRA-2591 — containing nothing but a shortened link. It carried a cross-site scripting payload written to take an administrator's session cookie; hundreds of thousands of password guesses hit the login page at the same time. On 6 April a guess worked. The attackers silenced notifications, changed the attachment upload path so that uploaded JSP files would run, and began copying home directories. On 9 April they installed a JAR that saved every password used to log in, then triggered password-reset mail to the infrastructure team; one replacement password its owner chose also opened a local account with sudo on brutus.apache.org — and that was root. Apache noticed about six hours later and shut the services down. On 13 April it published the sequence hour by hour with its own faults named: JIRA running with too much privilege, one password serving both a web application and sudo, hashes stored unsalted. Atlassian disclosed the same week that a customer database from before July 2008, its passwords in plain text, had been left in place — inactive, the company said, but it should have been deleted.

Also that month · 9–15 April

Not Worth Breaking the Cycle

On Friday 9 April 2010 Tavis Ormandy, a Google information security engineer, posted to the Full Disclosure list a flaw in the Java Deployment Toolkit, a plug-in installed with Java on Windows. Its launch method barely checked the address it was handed, so a web page could pass arbitrary arguments to javaws — among them one that fetched and ran a JAR from a network path. Everything from Java SE 6 Update 10 onwards was affected. Sun had been told, Ormandy wrote, and "they informed me they do not consider this vulnerability to be of high enough priority to break their quarterly patch cycle"; he published anyway, because "the simplicity with which this error can be discovered has convinced me that releasing this document is in the best interest of everyone except the vendor", and gave instructions for switching the control off. Turning off the Java plug-in was not enough, he wrote, because the toolkit was installed separately and could itself install and downgrade Java without prompting — so keeping current was no defence either. Oracle, which had owned Sun only since January, shipped Java SE 6 Update 20 out of cycle on 15 April. The years when Java was the exploit kits' preferred door are in January 2013.

India desk · April 2010

Shadows in the Cloud

On 6 April 2010 the Information Warfare Monitor — the Citizen Lab in Toronto and Ottawa's SecDev Group — published Shadows in the Cloud with the Shadowserver Foundation, eight months' work by Ron Deibert, Rafal Rohozinski, Nart Villeneuve, Greg Walton and Shadowserver's Steven Adair. From 44 compromised computers they recovered one apparently encrypted diplomatic correspondence, two documents marked SECRET, six RESTRICTED and five CONFIDENTIAL, identified as the Indian government's — though the report said it had no direct evidence the files came off government machines rather than personal ones. With them were assessments from a member of the National Security Council Secretariat on Assam, Manipur, Nagaland and Tripura; 99 documents from the missions in Kabul, Moscow, Dubai and Abuja; papers on the Pechora and Iron Dome missile systems and Project Shakti; and 1,500 letters sent from the Dalai Lama's office in 2009.

Control ran through Twitter, Google Groups, Blogspot, Baidu blogs and Yahoo! Mail down to core servers in China, and tied back to two individuals in Chengdu, one linked to the hacking underground and to the University of Electronic Science and Technology of China. Chengdu also holds a People's Liberation Army signals bureau; the authors called such correlations "loose at best" and stated they had "no evidence in this report of the involvement of the People's Republic of China (PRC) or any other government". Their reading: the network was run from China by people with strong ties to its criminal underground. China's foreign ministry rejected the implication, repeating that hacking is illegal under Chinese law and that China is itself a target of it; the Defence Ministry in Delhi was reported to have ordered a fact-finding inquiry. The researchers had told Canadian authorities in December 2009 and India's National Technical Research Organisation in February 2010; there was no settled way to tell a government its files were being read, a gap CERT-In's six-hour reporting rule later closed from the other side.

AI Tech desk · April 2010

Apple buys Siri, terms undisclosed

On 28 April 2010 Apple confirmed that it had bought Siri Inc., the start-up SRI International had spun out in 2007; terms were not disclosed, and the confirmation came through one of Siri's own board members rather than an announcement. What Apple had bought was the app that had been in the App Store since February, its thirty-odd outside services, and the people who built it. Behind it lay CALO, a DARPA-funded programme SRI describes as "the largest-known AI project in U.S. history"; the company had raised $24 million in two rounds. Eighteen months later the name came back as part of the iPhone 4S. On 12 April Google had bought Plink, a British start-up whose PlinkArt app identified paintings from a photograph, and put its two founders on Google Goggles — the beginning of the habit of pointing a camera at a thing to ask what it is.

Digital Guard desk · April 2010

Symantec buys PGP and GuardianEdge

On 29 April 2010 Symantec agreed to buy two encryption companies: PGP Corporation, for about $300 million in cash, and GuardianEdge, for about $70 million. PGP Corporation was formed in 2002 around the Pretty Good Privacy software Phil Zimmermann released in 1991, and sold desktop, e-mail and file encryption with a key-management server behind it; GuardianEdge, already a Symantec partner, made full-disk and removable-media encryption and was expected to strengthen Symantec's standing with government buyers. Symantec said it would standardise on PGP's key-management platform, and Francis deSouza, who ran its enterprise security group, put the aim as using encryption "in an intelligent and policy-driven way". Both deals closed that June; PGP Desktop became Symantec Encryption Desktop, its server Symantec Encryption Management Server, and the business passed to Broadcom in 2019, the PGP name living on chiefly in the OpenPGP standard. Eight days earlier Microsoft had dropped Forefront Protection Manager and said Forefront Endpoint Protection 2010 would be managed from System Center Configuration Manager instead — anti-malware as a feature of the machine-management console, where it has stayed.

⏳ Time capsule — April 2010

  • On 3 April the Wi-Fi iPad went on sale in the United States, nine weeks after Steve Jobs showed it in San Francisco on 27 January; Apple said 300,000 were sold on the first day, and the Wi-Fi and 3G model followed on 30 April.
  • On 14 April Eyjafjallajökull, in southern Iceland, began the eruption whose ash closed European airspace from 15 April; some 95,000 flights had been cancelled by 21 April, the largest shutdown of air traffic since the Second World War.
  • On 20 April an explosion aboard the Deepwater Horizon drilling rig in the Gulf of Mexico, about 41 miles off the Louisiana coast, killed eleven workers.
  • On 25 April, at the DY Patil Stadium in Navi Mumbai, Chennai Super Kings beat Mumbai Indians by 22 runs — 168 for 5 against 146 for 9 — to take the Indian Premier League for the first time; Suresh Raina, unbeaten on 57, was player of the match.
Where it stands today — 2026

The month the defence was the fault

April 2010 is the first month in which the industry watched its own product disable, at scale, the machines it had been sold to protect. McAfee's account of the cause was procedural — a change to its testing environment had let an untested file out — and so were its remedies. The structural fact went unaddressed, because it could not easily be: security software earns its keep by running with the deepest privileges a system has and by updating faster than any change-control board could approve, and both properties mean that a defect in the defender travels with the speed and reach of an attack. Fourteen years later a content update to CrowdStrike's Falcon sensor put millions of Windows machines into the same condition, each again needing a person in front of it: July 2024.

The smaller arguments of April 2010 settled more cleanly. Ormandy's position — that a flaw simple enough for anyone to find is not made safer by waiting for the next quarterly release — is now ordinary practice, a deadline attached to a private report as a matter of course, and Java's long spell as the exploit kits' preferred door runs through January 2013. Apache's decision to publish its own timeline with its own mistakes in it reads in 2026 like the beginning of a convention rather than an eccentricity. The espionage the Shadow report described did not stop, and India answered it slowly: a reporting regime first, and then, in 2023, a general law on personal data, set out on our India desk.