On Friday 17 February, Tavis Ormandy of Google's Project Zero was working on a fuzzing project when the test data came back wrong — corrupted in a way his own code could not explain. Looking closer, he found fragments of other people's web sessions embedded in pages returned by sites that had nothing to do with one another, except that all of them sat behind Cloudflare, the content-delivery and security company that then fronted some five and a half million websites. Unable to raise the right people through ordinary channels at the end of a working week, he posted eight words publicly: "Could someone from cloudflare security urgently contact me." Cloudflare had a team assembled in San Francisco within about half an hour.
The bug was five months old. On 22 September 2016, Cloudflare had begun migrating features to a new HTML parser called cf-html; the change in buffering exposed a latent flaw in the older, Ragel-generated parser it was replacing, where the check for the end of a buffer used an equality test a pointer could step past. When certain malformed HTML crossed an edge server, the machine appended whatever sat in memory beyond the buffer — session cookies, authentication tokens, POST bodies belonging to whichever other requests had passed through the same process. The worst period ran from 13 to 18 February, after the email-obfuscation feature joined the new parser, when about one request in 3.3 million triggered it — and search engines had been dutifully caching the results for months.
Cloudflare's response was fast and, six days on, unusually candid. An initial mitigation — switching off email obfuscation worldwide — was live 47 minutes after the company received details; all three affected features were disabled globally inside seven hours. The harder work was archaeology: with Google, Bing, Yahoo and others, engineers hunted leaked fragments out of search caches, and the company's disclosure on 23 February counted 770 cached URIs across 161 domains. Ormandy, browsing caches himself, reported finding private messages from dating sites, password-manager data and hotel bookings. In a follow-up on 1 March, chief executive Matthew Prince estimated the bug had fired 1,242,071 times and said there was no evidence anyone had exploited it before Ormandy found it — a conclusion Ormandy publicly regarded as more reassuring than the evidence allowed.
What unsettled people was not the count of victims — none was ever confirmed — but the shape of the failure. Some five and a half million sites had inherited one bug because they shared one intermediary, and the leak respected no boundary between customers: a request to any site behind Cloudflare could return fragments of any other's traffic. Cautious security teams rotated passwords wholesale; Uber, Fitbit and OkCupid spent the week answering for infrastructure they did not operate. The timing had its own irony. The industry had just left the RSA Conference in San Francisco, where on 14 February Microsoft's president, Brad Smith, proposed a Digital Geneva Convention to shield civilian infrastructure from state attack. The rest of the month demonstrated that civilian infrastructure could fail perfectly well on its own.
The day SHA-1 stopped being theoretical
On 23 February, Google and the CWI institute in Amsterdam published two PDF files that differ in content but share a single SHA-1 hash — the first practical collision against a function that had anchored digital signatures, version control and certificate chains since 1995. The attack, led by Marc Stevens of CWI with Google's security team and named SHAttered, built on cryptanalysis Stevens had published years earlier and cost roughly nine quintillion SHA-1 computations: 6,500 processor-years plus 110 GPU-years, compressed by parallelism into months, an effort Google put at around $110,000 if rented from a cloud at 2017 prices. The weakness had been understood since 2005, and public certificate authorities had been barred from issuing SHA-1 TLS certificates since the start of 2016. The demonstration claimed its first casualty within a day: on 24 February a WebKit engineer committed both PDFs to the project's Subversion repository to test a defence, and the repository — which used SHA-1 to deduplicate files — seized up and stopped accepting commits.
The typo that turned off the internet
At 9.37 on the morning of 28 February, Pacific time, an engineer on the Amazon S3 team was debugging the storage service's billing system and ran an established playbook command meant to take a small number of servers offline. One parameter was mistyped. The command removed a far larger set, including the machines running the subsystems that tracked where every object in the region lived, and S3's us-east-1 region in Northern Virginia — the oldest and largest — went dark for roughly four hours while systems that had not been fully restarted in years came slowly back. The dependent casualties made the point better than any architecture diagram: Slack file sharing, Trello, Quora, connected lightbulbs and thermostats, and Amazon's own service-health dashboard, whose status icons were stored in S3 and so could not change colour to admit anything was wrong. Amazon published an unusually plain post-mortem within days and changed the tool to remove capacity slowly, never below a subsystem's minimum. Nobody attacked anything; availability failed anyway.
3.2 million cards, one admission
On 9 February, Hitachi Payment Services confirmed what Indian banking had been circling since the previous autumn: malware planted in its systems — the company processed ATM and point-of-sale transactions and managed YES Bank's ATM network — had compromised debit cards between 21 May and 11 July 2016. The final forensic audit, the company said, established a sophisticated injection of malware that concealed its tracks, and the volume of data actually copied could not be ascertained. It was a reversal: in October 2016 the company had said an interim assessment found no evidence of a breach. By then the scale was already public — banks had blocked or reissued some 3.2 million debit cards, the largest replacement exercise Indian banking had seen, after fraudulent withdrawals surfaced in China and the United States on cards whose owners were in India. The National Payments Corporation of India had put confirmed losses at ₹1.3 crore, across 641 customers of 19 banks.
The rest of the month showed a central bank recalibrating. On 8 February the Reserve Bank of India said it would create a permanent inter-disciplinary Standing Committee on Cyber Security, and on 28 February it constituted the panel — eleven members, chaired by executive director Meena Hemchandra — to track emerging threats and recommend policy, replacing episodic expert committees with standing machinery. The context was the government's post-demonetisation push of hundreds of millions of people towards digital payment, three months after the note withdrawal of November 2016. The reader knows what the committee could not: that the defining test of Indian payment security would be breach reporting itself — a thread that runs from here to CERT-In's six-hour rule of 2022 and the data protection act of 2023.
TensorFlow 1.0, and moderation by machine
On 15 February, at its first TensorFlow Dev Summit in Mountain View, Google released TensorFlow 1.0 — the machine-learning framework it had open-sourced fifteen months earlier — with a stable API developers could finally build against, compatibility with the higher-level Keras library, and an experimental compiler called XLA. It was plumbing news, which is why it mattered: TensorFlow became the default substrate of the deep-learning boom, and though PyTorch later took the research crowd, the compiler work runs in a straight line to the systems that train today's models. On 23 February, Alphabet's Jigsaw unit released Perspective, an API that scored comments for toxicity, trialled with the New York Times, the Guardian, the Economist and Wikipedia — the most visible attempt yet to make moderation a machine-learning problem, and an early lesson in how models absorb the prejudices of their training data. And on 10 February, DeepMind posted research in which agents gathering apples learned, as the apples thinned, to knock each other out of the game with beams — a finding about incentives, not malice, though it read differently in the headlines.
Sophos buys a neural network
On 8 February, Sophos agreed to buy Invincea, a Fairfax, Virginia firm whose X product used deep-learning neural networks to catch malware no signature had seen, for $100 million in cash with an earn-out of up to $20 million; Invincea's government-facing research arm was carved out beforehand, and founder Anup Ghosh went with the deal. It was the pattern of the era in one transaction: the self-styled next-generation vendors had spent years declaring the signature dead, and the incumbents decided it was cheaper to buy the mathematics than to keep disputing it — Invincea's networks resurfaced a year later as the deep-learning engine inside Sophos's Intercept X. The same month, Kaspersky Lab announced commercial availability of KasperskyOS, a microkernel operating system built from scratch since 2002 — deliberately no Linux in it — debuting on a Kraftway network switch and aimed at industrial controllers and embedded devices no antivirus agent could protect. Within the year, Kaspersky's harder problem would be governments, not malware.
⏳ Time capsule — February 2017
- On 5 February the New England Patriots, trailing 28–3 in the third quarter, beat the Atlanta Falcons 34–28 in Super Bowl LI — the first Super Bowl decided in overtime, and Tom Brady's fifth title.
- Michael Flynn resigned as US national security adviser on 13 February, twenty-four days into the job, over his account of pre-inauguration conversations with Russia's ambassador.
- NASA announced on 22 February that the dwarf star TRAPPIST-1, thirty-nine light-years away, hosts seven roughly Earth-sized planets, three of them in the habitable zone.
- At the Academy Awards on 26 February, La La Land was mistakenly announced as Best Picture after the presenters were handed the wrong envelope; the award belonged to Moonlight.
Everyone downstream
Nine years on, Cloudbleed's ledger remains strange: one of the decade's most spectacular leaks, and not one confirmed victim. What lasted was the lesson about concentration. Cloudflare listed on the stock exchange in 2019 and now fronts a far larger share of the web than it did in 2017, so its bad days — the runaway regular expression of July 2019, the November 2025 outage that briefly unplugged some of the world's most-visited services — are planetary within minutes. The deeper fix was linguistic. The industry's slow move away from parsers written in languages where a pointer can walk off the end of a buffer hardened into explicit government policy, and Cloudflare itself rebuilt its proxy layer in memory-safe Rust.
SHA-1 died the way hash functions do — slowly, then in pieces: a far cheaper chosen-prefix collision arrived in 2020, NIST set a retirement deadline of 2030, and Git's migration to SHA-256 remains unfinished in 2026, because repositories have an inertia mathematics lacks. Amazon's us-east-1 kept its habit of reminding everyone where the internet physically lives, most recently in October 2025. And the month's quietest story set its longest precedent: Yahoo, which on 15 February notified users that forged cookies had been used to open their accounts, conceded $350 million off its sale price to Verizon six days later — the clearest case yet of a breach priced, in public, into the sale of a company. A breach, it turned out, is eventually a line item. WannaCry was ten weeks away.