Supply chain attacks that had no CVE on day one

109 real attacks, from 2009 to today. Every one shipped as a normal update from a source the world already trusted. On the day each landed, no scanner had a name or a number for it. But in every single one, a file inside the release had gained a power it never had in the version before. That is the change Vigilance reads, before you install.

Reconstructed. Built from public artifacts, vendor advisories and post-incident reports. This is not a CVE feed and not a byte-for-byte replay.

Every incident on this page shipped as a normal update from a source the world already trusted. In each one, a file inside the release gained a power it did not have in the version before it. That is the change Vigilance reads, and it reads it before you install.