The vulnerability that defined the month — and, by several measures, the half-decade since — was reported quietly on 24 November 2021, when Chen Zhaojun of Alibaba Cloud's security team told the Apache Software Foundation about a flaw in Log4j 2, a free Java logging library embedded in software beyond counting. The bug, CVE-2021-44228, scored a perfect 10.0: if an attacker could get an application to log a short crafted string, Log4j's JNDI lookup feature would fetch and run code from a server the attacker controlled. Public disclosure came on 9 December, and the first widely shared demonstration was almost absurd — typing the string into a Minecraft chat window was enough to take over the server that logged it.
Within a day it had a name, Log4Shell, and the scale had begun to sink in. The trigger worked almost anywhere text was logged: researchers who renamed an iPhone to contain the payload drew callbacks from Apple's iCloud servers, and a Steam profile could do the same. Cloudflare said it found exploitation attempts in its own logs dating back to 1 December, more than a week before disclosure. By mid-month, Microsoft and Mandiant were reporting that state-linked groups from China and Iran were experimenting with the exploit, and ransomware crews had begun folding it into their tooling alongside the ordinary crush of coin-miners and botnets scanning the whole internet, methodically, for anything that would answer.
The response set records of its own. CISA director Jen Easterly told industry executives on a 13 December call that the flaw was "one of the most serious I've seen in my entire career, if not the most serious", and an emergency directive on 17 December gave US federal civilian agencies until 23 December to find and fix it. The fixes themselves needed fixing: version 2.15.0 was followed by 2.16.0 on 13 December after a bypass surfaced, then 2.17.0 within the week after a denial-of-service flaw, so defenders patched the same systems three times before New Year. On 20 December, Belgium's Ministry of Defence confirmed that part of its network had been attacked through Log4Shell four days earlier — the first NATO defence ministry known to be hit.
Behind the noise sat a fact the industry preferred not to dwell on: Log4j was maintained by a handful of volunteers, who spent those weeks shipping fixes without pay while absorbing public criticism for a feature added years earlier. The fuller reckoning arrived in July 2022, when the US Cyber Safety Review Board made Log4j the subject of its first-ever report and concluded the vulnerability was "endemic" — that unpatched copies would remain in systems for a decade or longer, and that organisations should plan to keep finding them. Five years on, that forecast has held. December 2021 is the month the software industry learned, in public and over Christmas, exactly how little it knew about what was inside its own software.
Kronos goes dark for Christmas
Late on Saturday 11 December, Ultimate Kronos Group discovered ransomware in the Kronos Private Cloud, the hosted environment running workforce-management and payroll products — Workforce Central, TeleStaff, healthcare and banking scheduling — for thousands of organisations. The company's guidance was blunt: expect the systems to be unavailable for up to several weeks, and consider "alternative business continuity protocols". The timing could scarcely have been worse. Employers that clocked staff in and out through Kronos entered the holiday pay period with no system of record: the American Hospital Association warned its members within days, New York's Metropolitan Transportation Authority and the City of Cleveland reverted to manual timekeeping, and payroll offices cut cheques by hand or paid from stale data. Some employees were underpaid for overtime and holiday shifts well into January, and the lawsuits that followed ended in a $6 million settlement in 2023. UKG said it found no connection to Log4Shell; the month simply contained both.
The year closed the way it ran
On the night of 4 December, analysts at the blockchain-security firm PeckShield watched a BitMart hot wallet drain steadily to an address they labelled, with unusual candour, "BitMart Hacker". The exchange confirmed "a large-scale security breach" the next day and paused withdrawals; PeckShield put the losses at roughly $196 million across Ethereum and Binance Smart Chain wallets, while BitMart's chief executive estimated about $150 million, blamed a stolen private key, and promised to compensate users from company funds. A week later, on 11 December, AscendEX lost an estimated $77 million from its own hot wallets — the figure again coming from researchers rather than the company. DeFi bled in parallel: Vulcan Forged, a blockchain-gaming platform, said attackers obtained private keys to user wallets and took roughly $140 million in tokens, and Grim Finance lost about $30 million to a contract exploit. None of it was novel by December 2021, and that was the point. The year ended as it had run — with fortunes sitting in places one key could empty.
The night the PM's account adopted Bitcoin
In the early hours of 12 December, the more than 73 million followers of Prime Minister Narendra Modi's Twitter account briefly received investment news: a tweet announcing that India had officially adopted Bitcoin as legal tender, that the government had bought 500 BTC, and that the coins were being distributed to residents through a link. The tweet was deleted within minutes. The Prime Minister's Office said that morning that the handle had been "very briefly compromised", that the matter had been escalated to Twitter, and that the account had been secured immediately. Twitter confirmed it had secured the account as soon as it became aware, and said there were no signs that other accounts were affected. It was the second incident around the Prime Minister's online presence — the Twitter account of his personal website had been hijacked in September 2020, that time too with a cryptocurrency appeal.
The rest of India's security December belonged to Log4Shell. CERT-In issued its own advisory on the flaw in mid-December, joining the queue of national agencies urging immediate patching, and the country's IT-services firms — whose engineers run the back offices of half the world's enterprises — spent the holidays auditing twice over: once for clients abroad, once for systems at home. Banks, brokerages and government portals all sat on Java stacks of precisely the vintage the bug favoured. The scramble previewed an argument that took statutory form within months, when CERT-In's April 2022 directions imposed a six-hour incident-reporting clock on Indian organisations — the moment the habit of quietly absorbing incidents began, on paper at least, to close.
Quiet papers for a loud decade
On 8 December 2021, DeepMind announced Gopher, a 280-billion-parameter language model that beat the previous state of the art on the great majority of tasks it was evaluated on, alongside RETRO, a far smaller model that matched systems many times its size by looking passages up in a vast text database rather than memorising them. Google answered within the week with GLaM, a 1.2-trillion-parameter mixture-of-experts model that activated less than a tenth of itself for any given input — the sparse design most frontier systems now use. On 16 December, OpenAI unveiled WebGPT, a GPT-3 variant trained with human feedback to browse the web and cite its sources; and Anthropic, then in its first year, released its first alignment paper, proposing an assistant that should be helpful, honest and harmless. Few outside the field noticed any of it. Scale, sparsity, retrieval, human feedback: every load-bearing idea of the chatbot era shipped, in draft, that December.
Every product becomes a Log4j scanner
For the security vendors, the month was one long incident response. Within days of the 9 December disclosure, every major endpoint firm had shipped detection rules for the exploit string and its fast-multiplying obfuscations, and the products themselves turned into scanners: Microsoft folded a dedicated Log4j dashboard into its Defender portal late in the month, hunting vulnerable copies of the library across devices, software inventories and container images, while rivals bolted similar audits onto their consoles. Bitdefender, whose honeypots had been drawing exploit attempts since 10 December, supplied the month's landmark detection on 11 December: Khonsari, a .NET ransomware pushed through Log4Shell onto Windows machines — the first ransomware family observed arriving through the flaw — though within two days the same attackers had switched to dropping a remote-access trojan. Speed carried a price: by 23 December, Defender's new Log4j scanner was raising false "sensor tampering" alerts on Windows Server 2016 machines, which Microsoft spent the holidays suppressing. The emergency tooling never stood down; Log4j checks are still a fixture of those consoles in 2026.
⏳ Time capsule — December 2021
- Amazon Web Services went down three times in sixteen days — on 7, 15 and 22 December; the first outage, in its Northern Virginia region, silenced Alexa speakers and Ring doorbells and idled Amazon's own delivery drivers at the peak of the holiday rush.
- Max Verstappen passed Lewis Hamilton on the final lap of the Abu Dhabi Grand Prix on 12 December to win his first Formula One title, after a safety-car call still argued about today.
- Spider-Man: No Way Home opened on 17 December to a $260 million US weekend — the second-biggest ever at the time, in a cinema year the pandemic had hollowed out.
- The James Webb Space Telescope launched on Christmas morning, 25 December, aboard an Ariane 5 from Kourou — decades and roughly ten billion dollars in the making.
Still in the walls
Log4Shell did what the review board said it would. Exploitation never stopped — state-linked intrusions through unpatched VMware Horizon servers were still being documented deep into 2023 — and scanners still turn up vulnerable builds today, buried in appliances whose vendors have forgotten they exist. The episode gave the software bill of materials its political moment and made open-source sustainability a boardroom phrase, though the arc this archive traces suggests the lesson kept needing to be relearned: the XZ Utils backdoor of March 2024 and the npm worm of September 2025 travelled through the same unpaid, overtrusted plumbing. The dependency did not change. The awareness did, slightly.
The month's other stories ran forward on schedule. Conti, whose ransomware surfaced on Shutterfly's manufacturing network as the month closed, backed Russia's invasion in February 2022, saw its internal chats leaked in reply, and dissolved by summer — its people scattering into the groups that fill this archive's later years. Kronos taught a lesson about payroll as critical infrastructure that February 2024's Change Healthcare month would repeat at national scale. The exchange thefts kept compounding, through Ronin's $625 million in March 2022 to Bybit's record haul in February 2025. The Vault continues backwards from here, into the year that made all of it feel inevitable.