On September 17, 2024, thousands of pagers carried by members of Hezbollah detonated near-simultaneously across Lebanon and parts of Syria. The following day, walkie-talkies did the same. Dozens of people were killed — including civilians and children — and thousands injured, in hospitals, streets, and homes. The operation was widely attributed to Israel, which did not claim it at the time; Lebanon's government and the UN condemned it, and the legality of an attack detonating devices in civilian spaces was immediately and sharply contested.

We cover it here because of what it established about hardware. The devices had been compromised long before they were used — explosives and triggering mechanisms reportedly built into the units during manufacture or distribution, through a supply chain that the eventual owners believed they had chosen carefully. Hezbollah had adopted pagers precisely as a security measure, deliberately retreating from smartphones to avoid electronic surveillance. The devices they chose to be safe were the vector.

The lesson generalises uncomfortably. Every organisation on earth buys hardware through chains it cannot fully see: white-label devices, contract manufacturers, distributors, resellers. Software supply-chain attacks — SolarWinds, XZ Utils, the npm worms — at least leave forensic artefacts that a defender can eventually find. A device altered before it ever reaches you offers no such courtesy. In the months afterward, procurement conversations in defence, telecoms, and critical infrastructure changed in a way that has not reversed: provenance, custody, and tamper-evidence moved from paperwork exercises to genuine requirements. September 2024 is why.

Also that month · The city stops

Transport for London, and the cost of caution

On September 1, Transport for London disclosed a cyberattack that would disrupt the capital's transport systems for weeks. Contactless journey histories and Oyster refunds were affected, staff lost access to systems, and TfL later confirmed that bank account details of a few thousand customers may have been accessed. A 17-year-old was arrested in connection with the incident. Two details stood out: the disruption came largely from TfL's own defensive shutdowns rather than the attacker's actions — the right call, taken at real public cost — and the arrest was another reminder that some of the year's most disruptive intrusions were the work of teenagers.

Also that month · Trust, revoked

Kaspersky's American ending

September brought an unusual coda to a long geopolitical story: following the US ban on Kaspersky products, the company's American customers found their antivirus automatically removed and replaced with a different vendor's software — UltraAV — in some cases without clear warning. The transition, however defensible commercially, unsettled security professionals for a simple reason: it demonstrated that any security agent with update privileges can replace itself with something else entirely. The industry spent a fortnight arguing about the boundary between an update and a substitution — a debate that would look prescient ten months later, when a different vendor's update took down eight and a half million machines.

India desk · September 2024

Star Health sues Telegram

India's largest health insurer spent September in an unfamiliar posture: as plaintiff. After customer data began circulating through Telegram chatbots that would return individual policyholders' records on request, Star Health went to court against the messaging platform itself, seeking to have the bots taken down — an Indian insurer suing a global messaging service over the distribution of its own stolen data. The move set up the far larger disclosure that followed weeks later, when the seller surfaced publicly claiming more than 31 million customers' records. It also posed a question Indian law was not yet equipped to answer cleanly: when stolen data is served through a platform, what is the platform's obligation — and who does a breached company sue first, the thief or the pipe?

AI Tech desk · September 2024

OpenAI's o1, and the cost of thinking

On 12 September 2024 OpenAI released o1-preview and o1-mini to ChatGPT Plus and Team subscribers, models trained to work through a problem step by step before answering rather than to answer immediately. The pitch was a second axis of improvement: not a larger model, but a longer pause. The reasoning itself stayed hidden — OpenAI declined to show the chain of thought, arguing the model needed freedom to think unpoliced, while API customers were billed for tokens they could not read, a bargain researchers disliked from the first week. Later that month Meta used its Connect conference on 25 September to announce Llama 3.2, its first open multimodal release, pairing vision-capable 11B and 90B models with small text-only models sized for phones and edge devices. On 29 September Governor Gavin Newsom vetoed SB 1047, California's frontier-model safety bill, calling it poorly targeted while leaving the door open to a narrower successor. Two years on, every major laboratory ships a reasoning model; September 2024 is where that stopped being a research curiosity.

Digital Guard desk · September 2024

Microsoft convenes the kernel question

On 10 September 2024 Microsoft gathered its endpoint security partners at Redmond for a Windows Endpoint Security Ecosystem Summit — Broadcom, CrowdStrike, ESET, SentinelOne, Sophos, Trellix and Trend Micro, with government officials from the United States and Europe in the room. The subject was July: whether products that protect Windows should keep running inside its kernel, where a faulty update stops the machine rather than merely the product. What emerged was a direction, not a decision. Microsoft said it would design a new platform capability offering security functions outside kernel mode, developed with partner input, and pressed the case for staged, gradual rollouts — safe deployment practice as an industry norm rather than a vendor preference. Nothing was committed and no timetable was set; ESET stated publicly that kernel access must remain available to security products, and others were similarly guarded. A fortnight later, on 24 September, CrowdStrike's Adam Meyers apologised for the outage before a House subcommittee.

⏳ Time capsule — September 2024

  • Security conferences quietly rewrote their supply-chain tracks; "hardware provenance" became a session title everywhere.
  • Apple shipped the iPhone 16 with an AI-first pitch, as the industry's attention turned decisively to on-device intelligence.
  • Sales of pagers — a technology many assumed extinct — briefly became a subject of international news analysis.
  • In India, festive-season shopping ramped up alongside the year's steepest wave of fraud advisories.
Where it stands today — 2026

Provenance became a requirement

Two years on, September 2024's legacy is written into procurement policy rather than headlines. Hardware provenance, tamper-evident logistics, and custody documentation are now standard clauses in defence and critical-infrastructure contracts, and the phrase "trusted supplier" carries a weight it did not before. The month also completed a shift this archive keeps returning to: 2024 was the year attackers stopped targeting their victims directly and started targeting whatever their victims trusted — software updates, support vendors, cloud tenancies, and, that September, the physical devices themselves. Everything in these pages since has been a variation on that theme.