When Microsoft's August 2020 Patch Tuesday fixed CVE-2020-1472, the bulletin drew little attention: a privilege-escalation flaw in Netlogon, one line among dozens. On 11 September, Tom Tervoort of the Dutch security firm Secura published what that patch had been quietly protecting against, and gave it a name — Zerologon. Netlogon, the protocol Windows domain controllers use to authenticate the machines of their own domain, encrypted its handshake with AES-CFB8 using an initialisation vector fixed at sixteen zeroes. Feed that handshake nothing but zeroes and, in one attempt out of 256, the mathematics cooperates. An attacker on the network needed no password and no account — only a few seconds of retries — to be accepted as a domain controller.

Proof-of-concept exploits appeared on GitHub within hours of the write-up. From there the consequences were mechanical: an intruder with any foothold — one phished laptop, one forgotten test server — could impersonate a domain controller, set its machine-account password to empty, and inherit Active Directory whole: every account, every credential, every machine that trusted the domain. Secura said the full attack ran in about three seconds. NIST scored the flaw a perfect 10.0, and Tenable's year-end review would rank it the most critical vulnerability of 2020. For ransomware crews, whose craft is turning one compromised machine into every machine, the published exploit was not research. It was tooling.

The American response set the month's tempo. On Friday evening, 18 September, CISA issued Emergency Directive 20-04, ordering federal civilian agencies to apply the August update to every Windows domain controller by 11:59pm on Monday 21 September — a weekend deadline, justified in the directive's own language by the unacceptable risk the flaw posed to federal networks. Emergency directives exist for the rare cases in which waiting for a normal patch cycle is itself the danger; this one turned the weekend of 19 and 20 September into an unplanned shift for system administrators well beyond government. On 24 September, Microsoft confirmed what the deadline had assumed: it was tracking active exploitation, with public proof-of-concept code already folded into attacker playbooks.

What followed is why September 2020 keeps its place in this archive. In early October, Microsoft reported that the Iranian group it tracks as MERCURY was exploiting Zerologon in active campaigns; by late October, incident responders had documented Ryuk operators riding the bug from a single phished inbox to domain-wide encryption in about five hours. US agencies spent the autumn warning that state-sponsored actors were chaining it with VPN flaws against state and local networks, including some supporting elections. Microsoft's permanent fix — an enforcement mode that refuses insecure Netlogon connections outright — arrived in February 2021. The lesson outlasted the patch cycle: identity infrastructure was now the prize, and a single all-zero shortcut had nearly given it away.

Also that month · Ransomware in the wards

The night Universal Health Services went dark

In the early hours of Sunday 27 September, computers across Universal Health Services — one of America's largest hospital operators, with about 400 facilities in the United States and Britain — began shutting down one after another. Staff described screens failing overnight, phones dying with them, and wards reverting to paper charts; some ambulances were diverted to neighbouring emergency departments. The company's first statement admitted only an IT security incident. It later confirmed ransomware, and employees told reporters the ransom notes matched Ryuk — an attribution UHS itself never detailed. The company said its US systems were reconnected by mid-October, and that it found no evidence patient or employee data had been accessed, copied or misused. The bill arrived with its results the following February: $67 million pre-tax, most of it, the company said, lost operating income from reduced patient activity and the billing delays that followed. Contemporaneous reporting described it as one of the largest medical cyber-attacks in US history — a title later editions of this archive would not let it keep.

Also that month · The negligent-homicide file

A death in Düsseldorf, examined

The month's hardest story must be told whole. In the early hours of 10 September, ransomware identified by investigators as DoppelPaymer encrypted about thirty servers at Düsseldorf University Hospital, which withdrew from emergency care. A 78-year-old woman in a life-threatening condition was rerouted to Wuppertal, roughly thirty kilometres away; her treatment began about an hour later than it would have, and she died. Cologne prosecutors opened a negligent-homicide inquiry, and the case was reported worldwide as the first death caused by ransomware. The details were stranger: the intruders had entered through a Citrix flaw fixed since January, and addressed their ransom note not to the hospital but to the affiliated Heinrich Heine University, suggesting they believed that was their victim. When Düsseldorf police told them it was a hospital, the attackers withdrew the demand and handed over the decryption key. In November the prosecutors closed the inquiry with a conclusion this archive is obliged to carry: her condition had been so grave that the delay made no difference to the outcome. The first ransomware death, examined, was not one.

India desk · September 2020

A hijacked handle, and a Shenzhen database

In the small hours of 3 September, the Twitter account linked to the Prime Minister's personal website and mobile app — @narendramodi_in, followed by more than 2.5 million people — began asking Indians to donate cryptocurrency, bitcoin included, to the PM National Relief Fund. The tweets were signed John Wick, listed a Tutanota email address, and added a curious aside: that the group had not hacked Paytm Mall. That referred to a claim, circulated in late August under the same alias, that the e-commerce platform's data had been breached and ransomed — a claim Paytm Mall investigated and denied, saying it had found no evidence of a breach. Twitter confirmed it was aware, said it had secured the account, and the scam tweets were removed. It was, mercifully, a hijacking for petty fraud rather than an intrusion into anything of state.

Eleven days later, The Indian Express began publishing its investigation of Zhenhua Data, a Shenzhen company whose leaked Overseas Key Information Database tracked about 2.4 million people worldwide — among them more than 10,000 Indian individuals and organisations, from the President and Prime Minister to chief ministers, judges, scientists, journalists and athletes. Most entries were stitched from open sources: social media, public records, news. Zhenhua called the reporting untrue and denied links to the Chinese state; New Delhi constituted an expert committee under the National Cyber Security Coordinator to assess the revelations and report within thirty days. Nothing had been hacked, and that was the point that lingered: a foreign contractor had been quietly assembling dossiers on Indian public life from material India had published about itself.

AI Tech desk · September 2020

A byline for GPT-3, a licence for Microsoft

On 8 September, The Guardian ran an op-ed under the byline of a machine — "A robot wrote this entire article. Are you scared yet, human?" — assembled by its editors from eight essays GPT-3 produced when Liam Porr, a Berkeley undergraduate, fed it the paper's prompt. The paper disclosed the splicing in an appended note and said the piece took less time to edit than many human columns; researchers grumbled that the stitching, not the model, had made the argument — a quarrel that reads quaintly now that machine prose is ordinary. The month's more consequential news came on 22 September, when Microsoft announced an exclusive licence to GPT-3 itself, leaving OpenAI's API open to other developers but reserving the underlying model — the arrangement that grew into Azure OpenAI and the Copilot era. Between the two, on 13 September, Nvidia agreed to buy Arm from SoftBank for $40 billion in the name of AI computing; regulators around the world objected, and the largest chip deal ever attempted collapsed in February 2022.

Digital Guard desk · September 2020

The month everything became Defender

At its Ignite conference, held online from 22 September, Microsoft gathered its scattered security products under one name. Microsoft Threat Protection became Microsoft 365 Defender; Defender ATP became Microsoft Defender for Endpoint; the Office 365 and identity products took matching titles, and the threat-protection side of Azure Security Center re-emerged as Azure Defender, covering cloud and hybrid workloads. The company pitched the unified family as extended detection and response — XDR, the acronym of the season — and the branding has held ever since, the foundation of what became one of the industry's largest security businesses. The month's operational work belonged to the cover story: within days of the 11 September Zerologon write-up, endpoint and identity-protection vendors — Microsoft's among them — were shipping detection rules for the forged Netlogon handshake it described. And on 28 September, McAfee — one of the oldest names in anti-virus — filed for an initial public offering on the Nasdaq; it listed in October, raised $740 million, and inside two years had been sold to private-equity buyers and taken private once more.

⏳ Time capsule — September 2020

  • Yoshihide Suga became Prime Minister of Japan on 16 September, succeeding Shinzo Abe after his record-setting tenure.
  • US Supreme Court Justice Ruth Bader Ginsburg died on 18 September, aged 87.
  • The Indian Premier League opened in Abu Dhabi on 19 September — moved to the UAE by the pandemic, and played to empty stands.
  • Confirmed global Covid-19 deaths passed one million on 28 September, by Johns Hopkins University's count, nine months into the pandemic.
Where it stands today — 2026

The month the decade rehearsed

Zerologon set a template this archive keeps meeting again. The emergency directive with a countdown became the standard answer to internet-scale flaws — redeployed for Microsoft Exchange's ProxyLogon in the March 2021 edition and for Log4Shell in December 2021, each another weekend nobody in security operations got back. The deeper shift was in the target: Zerologon was an attack not on a server but on identity itself, and the years that followed — from the SolarWinds intrusions disclosed that December to the token forgeries and directory compromises chronicled through 2023 and 2024 — confirmed that whoever holds the domain controller, or its cloud successor, holds everything. The all-zeroes trick was patched in weeks. The idea it proved never went away.

The hospital thread runs just as straight through these pages. UHS's $67 million looked large until Ireland's entire public health service was encrypted in May 2021, and both were dwarfed when Change Healthcare stopped the flow of American medical payments in February 2024. Düsseldorf left something rarer: a prosecutor's refusal of the easy headline, and a reminder that the causal chain matters more than the story it would make. And India's September — a hijacked handle, a Shenzhen watch-list — reads now as the opening page of a story this archive follows through CERT-In's six-hour reporting rule in 2022 and the DPDP Act in 2023: a state learning, incident by incident, what its data was worth.