The exploit was already in the kits before anyone outside noticed. In the first week of January 2013 a flaw in Java 7 — CVE-2013-0422, a chain that reached a private object through a public method in the JMX management interface and then used reflection until the security check stopped applying — began appearing in the drive-by packs that rented browser exploitation out by the week. Kaspersky Lab, watching the distribution as it happened, placed it in Blackhole, Nuclear Pack and Red Kit, delivered through advertising networks that pushed readers of weather and news sites onto hosting servers; the Java archives carried names like Stretch.jar and UTTER-OFFEND.JAR, and the payloads came from the TDSS and ZeroAccess families. Kaspersky's own telemetry logged thousands of blocked attempts between 6 and 11 January.
The advisories came on 10 January. The CERT Coordination Center at Carnegie Mellon published Vulnerability Note VU#625617; the United States Computer Emergency Readiness Team, then part of the Department of Homeland Security, issued Alert TA13-010A the same day, saying reports indicated the vulnerability was being actively exploited and that exploit code was publicly available, and advising readers to "consider disabling Java in web browsers until adequate updates are available". Will Dormann of CERT told Brian Krebs that the flaw stemmed from a component Oracle had introduced with Java 7. Oracle shipped an out-of-band fix on 13 January as Java 7 Update 11 and raised the default security level from medium to high, so that unsigned applets required a click before running.
The advice did not go away when the patch arrived. CERT's note, revised into June 2013, kept a line unusual in the rhythm of patch-and-move-on: unless it was absolutely necessary to run Java in web browsers, disable it, even after updating to 7u11, to mitigate other Java vulnerabilities that might be discovered in future. Immunity's analysts had said only the reflection half was repaired. Apple went further, and did it remotely. Its XProtect list sets a minimum acceptable version for browser plug-ins; Apple raised that floor above the shipping Java build early in the month, lowered it when Update 11 appeared, then on 31 January raised it to 1.7.0_11-b22 when the newest build Oracle had published was b21. There was nothing left for Mac owners to update to.
It was the second emergency Java patch in five months. Oracle had published an out-of-band alert on 30 August 2012 for CVE-2012-4681 and shipped Java 7 Update 7 four days after that flaw became public — months, researchers said, after they had reported it. The market read the pattern. On 16 January Krebs described a cybercrime forum administrator offering an unpatched flaw in Update 11 itself at $5,000 a buyer, to two buyers only; Krebs wrote plainly that he had proven nothing, and on 2 April reported the thread was a hoax staged to learn the screen name he posted under. The same fortnight, on 8 January, Rails released fixes for CVE-2013-0156, a parameter parser that turned XML into Ruby objects and was on by default in every Rails application.
Five years of diplomatic post
On 14 January 2013 Kaspersky Lab published on a campaign it named Red October, investigated since the previous October after attacks on diplomatic agencies. Domain registration records and the timestamps in the collected executables put the start of the attacks, Kaspersky said, as far back as May 2007; the oldest command server domain it found had been registered that November. More than three hundred infected systems were counted at embassies, military installations and nuclear and aerospace research bodies in thirty-nine countries; the malware hunted files from cryptographic systems including Acid Cryptofiler, used in European institutions. One module existed only to resurrect the rest, sitting in Adobe Reader and Word to restore access from a document sent after a clean-up. Within days registrars and hosts were closing the sixty-odd command domains; Kaspersky's Costin Raiu said it was going down "for good". The month closed with two newspapers. On 30 January the New York Times said intruders had been in its network for four months, after the sources behind its reporting on the Chinese premier's family wealth; Mandiant, which it hired, said the antivirus in place caught one of forty-five pieces of malware. The Wall Street Journal said the next day that its Beijing bureau had been broken into. China's defence ministry denied it; what Mandiant did next belongs to February 2013.
The charges and the law
Aaron Swartz died on 11 January 2013. He was twenty-six, and was facing federal prosecution over the bulk downloading of academic articles from JSTOR through the Massachusetts Institute of Technology's network in late 2010 and early 2011: an indictment of 11 July 2011 charging wire fraud, computer fraud, unlawful access to a protected computer and reckless damage, and a superseding indictment of 12 September 2012 adding nine further felony counts. Prosecutors had offered six months in a low-security prison in exchange for a guilty plea to thirteen counts; he had refused it and was preparing for trial. The consequence for this magazine's beat arrived on 20 June 2013, when Representative Zoe Lofgren introduced H.R. 2454, styled Aaron's Law, with co-sponsors from both parties and a Senate companion from Ron Wyden. It would have written into the Computer Fraud and Abuse Act that breaching a terms-of-service agreement is not by itself a federal offence, defining access without authorisation as the circumvention of a technological or physical control — a password, encryption, a locked door. It stalled in committee, and again when reintroduced in April 2015.
Who may order the arrest
On 9 January 2013 the Union government issued an advisory to the states on Section 66A of the Information Technology Act, 2000 — the provision that made it an offence to send by computer any information that was grossly offensive or had menacing character. Under the advisory no arrest could be made under the section without the prior approval of an officer not below the rank of Inspector General of Police in metropolitan cities, or of a Deputy Commissioner of Police or Superintendent of Police at district level. It followed the case that made the section notorious. In November 2012 a twenty-one-year-old woman in Maharashtra was arrested over a Facebook post questioning the shutdown of Mumbai after Bal Thackeray's funeral, and a second woman was arrested for liking it; both were released on bail, and the cases against them were later dropped.
The advisory changed who signed the arrest order. It did not change the law. Section 66A stood on the statute book until 24 March 2015, when a two-judge bench of the Supreme Court — Justices J. Chelameswar and R.F. Nariman — struck it down in Shreya Singhal v. Union of India as vague and overbroad, contrary to Article 19(1)(a). Even that did not finish it: figures from ten states and Delhi showed hundreds of fresh cases under the dead section after the judgment, the Home Ministry had to tell police stations in July 2021 to stop, and the Court was still ordering remedial measures in October 2022. India in early 2013 had neither a data protection statute nor any duty to report a breach: the duty came by direction in 2022, the statute in 2023. The judgment that voided Section 66A is in March 2015.
A Query Box Over the Social Graph
Facebook announced the beta of Graph Search on 15 January 2013: a natural-language query box over the social graph — friends who live in a city, photos taken in a place, restaurants a colleague liked — running against a retrieval index its engineers described the same day. The company put the graph at more than a billion people and a trillion connections, said the feature returned only material already shared with the person searching, and released it as a limited preview in United States English. On 30 January IBM said it would supply a Watson system to Rensselaer Polytechnic Institute, the first university to receive one — the beginning of the machine's move out of the quiz studio and into other people's buildings, where the medical and commercial deployments of the following year would test what it could actually do. Most of Graph Search was withdrawn in June 2019, the natural-language box folded back into ordinary search; what survived was the idea that a database could be questioned in the words a person would use.
A Failed Certification and a Reorganisation
On 15 January 2013 the German laboratory AV-Test withheld its certificate from Microsoft Security Essentials and Forefront Endpoint Protection, which had blocked 78 per cent of zero-day attacks against an average of 92 per cent across the products tested. Microsoft disputed the method rather than the result: Joe Blackbird of its Malware Protection Center wrote that the firm's own telemetry showed only a minute fraction of customers had encountered the missed samples, and that the scoring leaned too heavily on zero-day cases; AV-Test's Andreas Marx defended testing with malware minutes old. On 23 January Symantec, then the largest vendor in the market, set out a reorganisation alongside its December-quarter results — fewer management layers, products built from its own research rather than acquisitions — and its chief executive of six months, Steve Bennett, said "our system is just broken". Kaspersky Lab launched Endpoint Security for Business in New York on 30 January, four tiers under a single console. Bennett was dismissed in March 2014; AV-Test would later rank Microsoft's built-in defences among the best.
⏳ Time capsule — January 2013
- On 14 January the Kumbh Mela opened at the confluence of the Ganga and the Yamuna at Allahabad, on Makar Sankranti; the temporary city built for it covered about 23.5 square kilometres, and estimates of the number who passed through before it closed on 10 March ran from eighty to a hundred and twenty million.
- On 16 January the Federal Aviation Administration issued an emergency airworthiness directive grounding the Boeing 787, hours after an All Nippon Airways aircraft made an emergency landing at Takamatsu on a smoke warning from an electrical compartment and nine days after a battery fire on a parked Japan Airlines 787 at Boston; it was the first time the FAA had grounded an airliner type since 1979, and all fifty delivered aircraft were on the ground by 17 January.
- On 21 January Barack Obama took the oath of office in public at the West Front of the United States Capitol, the ceremony falling on Martin Luther King Jr. Day; the constitutional swearing-in had been done privately in the Blue Room of the White House the day before.
- On 23 January the committee chaired by Justice J.S. Verma, with Justice Leila Seth and Gopal Subramanium, delivered its report on amendments to India's criminal law, thirty days after being constituted and having taken in more than seventy thousand submissions.
The default that came off
The advice of January 2013 was never rescinded so much as overtaken. Google announced in September 2013 that it would phase NPAPI out of Chrome, disabled it by default in April 2015 and removed the interface in September that year; Oracle announced the deprecation of the Java browser plug-in in January 2016; Mozilla dropped NPAPI from Firefox 52 in March 2017 and finished the work in Firefox 85 in January 2021. Java the language did not suffer for it and remains one of the most widely deployed runtimes in 2026. Java in the browser is gone, and the reasoning that removed it was the reasoning of that month: a component whose fixes keep arriving incomplete is not a thing to update but a thing to take out.
The other threads ran on. Aaron's Law never passed; the Computer Fraud and Abuse Act was narrowed instead by the Supreme Court on 3 June 2021, when Van Buren v. United States held, six to three, Justice Barrett writing, that using authorised access for an improper purpose does not exceed it — close to what the bill had asked of Congress, from another branch eight years later. The newspaper intrusions of 30 and 31 January led into February 2013, and the work Mandiant published there led on to the indictment in May 2014 of five officers of a Chinese army unit — charged not over the newspapers but over intrusions at American manufacturers and a steelworkers' union. In India, Section 66A was struck down and went on being used. This is where the Vault begins: the oldest edition in the archive, the restorations from here running backwards into 2012 and before.