L-Re · Incidental Research
The Signature Was the Passport
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# The Signature Was the Passport *USB Last Hops, Stolen Code-Signing, and the July 2010 Public Life of an Industrial Implant* **Prepared as a software-assurance and policy analysis** Compiled Date: 19 August 2026 Platform: Quiet Systems --- > **Research premise.** July 2010 is when a USB-borne, digitally signed Windows implant aimed at Siemens industrial software became a public Sense-to-Act story — a Passport failure (stolen or abused code-signing) on a last-hop Move (USB) toward an industrial Act surface (WinCC) — and the same month a Control Fabric leak put field-level lethal-action records into open collection. The shared trust failure is that operators assumed the internals of Act would stay unseen. ## Abstract **Research premise.** A mid-July malware story and a late-July war-diary dump are easy to file as unrelated beats: one is industrial, the other is military; one is a signed Windows implant, the other is a leak of Significant Activities. Read as a trust problem they are the same month. On 15–16 July 2010, Brian Krebs reported a Belarusian find dated 17 June and a Microsoft advisory on a Windows Shell vulnerability present in every supported edition; the implant used Realtek-signed drivers, spread by removable media rather than Autorun, and, in Frank Boldewin’s contemporaneous judgment, looked made for Siemens WinCC. By 19–22 July, as later compiled in Symantec’s November dossier, VeriSign had revoked a Realtek certificate and then a JMicron certificate, Siemens was investigating WinCC and related SCADA hosts, and the detection name had become W32.Stuxnet. On 25 July, WikiLeaks released the Afghan War Diary: more than 91,000 reports, about 15,000 withheld, written by soldiers and intelligence officers and mainly describing lethal United States military actions. This paper treats those objects as a software-assurance and policy problem, not as a weapons story and not as a finished attribution. The Passport failed first: Windows treated a vendor signature as a sufficient identity for a kernel driver. The last hop was a Move that did not need a network path. The possible Act surface was an industrial engineering host that operators had assumed would remain off the public ledger. The diary is the same class of failure on a different fabric: field records of lethal action that operators had assumed would remain inside the Army’s own Sense-and-report system. Physical plant consequence, a specific sabotage payload, IAEA or Iranian centrifuge statements, and any UAV-strike tally extracted from the diary are not July 2010 public Facts in this collection. Those unknowns are not safe defaults. A July Passport would have recorded signed-driver theft or abuse as a supply-chain identity failure and USB as the last-hop Move — without publishing a how-to. _Keywords: code-signing, product assurance, Passport, industrial control systems, WinCC, removable media, Control Fabric, Afghan War Diary, Sense-Move-Act, certificate revocation_ ## 1. Introduction: The Apparent Unrelatedness A July 2010 headline pair is easy to misread as two professions talking past each other. In the middle of the month, a little-known Belarusian antivirus firm and a security reporter put a USB-borne Windows implant into public view. Ten days later, WikiLeaks put more than ninety thousand Afghan field reports into public view. A reader who treats malware as an information-technology beat and war diaries as a journalism beat expects no shared object. The contemporaneous public record does not make that calculation. Both stories are about the internals of Act. Both puncture the same type of trust: that operators could keep those internals unseen.1 The disparity is easiest to misunderstand when the month is read as a recap. Under that reading, the implant becomes “Stuxnet,” the diary becomes “WikiLeaks,” a Congressional Research Service border-UAV primer becomes a third theater, and a January snapshot of the Pakistan campaign becomes a fourth. Later memory then supplies Iran, centrifuges, and a finished drone-kill count. The opened July file runs the other way. The implant is first a Passport failure: Windows treated a Realtek digital signature as a sufficient identity for a kernel driver. The removable drive is a last-hop Move toward machines that were not supposed to have an inbound network path. Siemens WinCC is a possible Act surface, named in July by an independent researcher and then by the vendor, not yet a proven plant event. The diary is a Control Fabric leak of Significant Activities and related intelligence notes, not a UAV study. Collapsing those plates into a five-signal highlight reel, or into later-memory attribution, corrupts the ledger LrrK exists to keep. This distinction matters. Software-assurance analysis can target what a system will accept as identity, how a payload can cross an air gap as a physical Move, and whether the command surface is owned tightly enough to be trusted after the fact. Product assurance adds a fourth question: whether the public record is complete enough that a later operator can reconstruct what was signed, what was revoked, and what remained installed. July 2010 answers the first two more cleanly than the rest. A signature was accepted. A removable drive was a sufficient last hop. A named industrial vendor opened an investigation. A field archive of lethal action left the Army’s own reporting system. Physical consequence at a named plant is not in the July public sources fetched here. Treating that gap as safety would be the opposite error. The argument developed here is that the trust failure is assumed invisibility of Act, not the later celebrity of the worm and not the later politics of the leak. LrrK’s objects earn their place only where they keep that claim on separate plates: a Passport for stolen or abused code-signing, a last-hop Move for USB, a possible Act surface for WinCC, a Control Fabric for the diary, and a Watch desk that records extra-theater UAV Act as continuity without rebuilding the Pakistan campaign already treated in sibling papers. October 2001, January 2009, and May 2011 are sibling files on clearance, inherited covert command and control, and mixed attribution; none is reopened here except as a one-line pointer. ## 2. What Mid-July Established The first public plate is Brian Krebs’s 15 July 2010 report, updated the next evening when Microsoft published an advisory. It is specific enough to quote and not specific enough to treat as a finished industrial-control record. VirusBlokAda, an antivirus company in Belarus, said that on 17 June its specialists found two new malware samples capable of infecting a fully patched Windows 7 system if a user viewed the contents of an infected USB drive in a file manager such as Windows Explorer. USB-borne malware was already common; most of it had used Autorun or Autoplay. This strain, the firm said, used a vulnerability in Windows shortcut handling rather than Autorun. Sergey Ulasen wrote that opening the infected storage device in a file manager that displayed icons was sufficient, and that the implant installed two drivers signed with the digital signature of Realtek Semiconductor Corp. He said he had reached Microsoft and Realtek and had received a response from neither. Jerry Bryant, Microsoft’s group manager of response communications, told Krebs the company was investigating the public claims and would take appropriate action when the investigation was complete.2 A 16 July update on the same Krebs post recorded that Microsoft had released an advisory on a Windows Shell vulnerability present in every supported version of Windows, with mitigations. Independent researcher Frank Boldewin, who had examined the samples, told Krebs they appeared to be looking for Siemens WinCC SCADA systems — machines used to control large, distributed industrial processes. “Looks like this malware was made for espionage,” Boldewin said.3 Those sentences are facts about what Krebs published against named people and against a same-day Microsoft advisory. They are not, without a dated Siemens plant statement, facts about a modified controller, a named facility, or a physical outcome. They are not a reproduction procedure. This paper names the failure classes and does not transcribe shortcut-handling, removable-media, or driver-installation methods from any primary. Microsoft’s own July 16 advisory, Security Advisory 2286198, is the vendor plate: “Vulnerability in Windows Shell Could Allow Remote Code Execution,” published that day as version 1.0. It was updated on 2 August when Microsoft issued bulletin MS10-046 for CVE-2010-2568. The July advisory is the July Fact; the August bulletin is a later closure, not a July event.4 Dave Forstrom’s Microsoft Security Response Center post the same day stated that the vulnerability was “most likely to be exploited through removable drives,” that the company had seen “only limited, targeted attacks,” and that “in the wild, this vulnerability has been found operating in conjunction with the Stuxnet malware.”5 Siemens’s public plate arrived in the same mid-July window. A media advisory reprinted by *Control Global* stated that the company was notified on 14 July about malware targeting Simatic WinCC and PCS 7, had assembled a team of experts, and was working with Microsoft and antivirus vendors. It said a Trojan spreading via USB sticks and using a Microsoft security breach searched infected computers specifically for those Siemens installations, urged customers to check WinCC hosts, named Trend Micro, McAfee, and Symantec as detecting vendors, and recommended avoiding USB sticks.6 Robert McMillan’s *Computerworld* story of 17 July quoted Siemens Industry spokesman Michael Krampe on the 14 July notification and on the customer outreach.7 Honesty requires four labels on the mid-July plate. Fact: by 15–16 July a named finder, a named reporter, a named Microsoft spokesman, and a Microsoft advisory had established a new public malware family that used removable media and Realtek-signed drivers. Fact: Boldewin named Siemens WinCC as the apparent object, and Siemens, notified on 14 July, publicly treated WinCC and PCS 7 as in scope. Inference, moderate: the implant was built to reach industrial process-control hosts rather than ordinary information-technology espionage targets. Judgment: the first public Sense-to-Act story of the month is a Passport failure on a last-hop Move toward a possible industrial Act surface. Unknown: a specific plant, a sabotage payload, and any physical consequence. July public sources fetched here do not prove those three. They do not make them safe. VirusBlokAda’s own English advisory page was not independently retrieved for this paper; the address later cited in secondary accounts returned not found. The June 17 find date and Ulasen’s description are therefore cited through Krebs, and Microsoft’s later August bulletin acknowledged Sergey I. Ulasen and Oleg Kupreev of VirusBlokAda among those who reported the shortcut-icon vulnerability. That acknowledgment is an August Fact about credit, not a substitute for the missing June page.8 ## 3. The Signature Was the Passport A digital signature on a kernel driver is not a decoration. It is an identity decision. Windows, in the configuration that industrial engineering hosts were encouraged to run, treated a trusted vendor signature as a sufficient Passport: the operating system would load the driver without the warning that an unsigned binary would have raised. The July public story is that two driver files carried Realtek’s name. The assurance failure is not that Realtek wrote industrial malware. The failure is that the Passport could be stolen or abused and still work. Ulasen’s description, as Krebs printed it, is the identity claim. Both drivers were signed with the digital signature of Realtek Semiconductor Corp., “a legitimate hi-tech company.” McMillan, two days later, recorded the same observation and the open question it created: it was unclear how the authors had obtained the signature; the fact might indicate that Realtek’s signing key had been compromised; the Taiwanese vendor could not be reached for comment.9 Those are facts about what July reporting said. They are not a finding, in the mid-July file, of how the certificate left Realtek, whether a token was stolen, whether a signing service was abused, or whether an insider participated. Mechanism of theft remains Unknown. Treating “not established” as “therefore the key was safe” would be the wrong inference. Treating a later novelistic reconstruction as a July Fact would be envelope inheritance. The Passport object is larger than one vendor. Code-signing is a supply-chain identity system. A semiconductor company signs drivers so that operating systems and administrators can distinguish a vendor’s own kernel code from unsigned strangers. Industrial environments lean on that distinction more heavily than ordinary offices do, because they often require signed drivers and because they often prohibit unsigned kernel code as a matter of policy. The July implant used that policy as a door. A Watch desk that records only “USB worm” has already lost the object. The removable drive is the Move. The signature is the Passport. Without the Passport, the last hop is a piece of media. With it, the last hop is a trusted identity arriving on a stick. LrrK’s Passport is the artifact that would have made this failure visible before it became a press story. A July Passport on an engineering workstation would have recorded the signer, the certificate serial, the timestamp, the revocation status, and the human disposition that accepted the driver. It would not have certified the host as safe. It would have maintained a signed, longitudinal identity story: who claimed to have written the kernel code, who actually signed it, and whether that claim still matched the vendor’s current list of valid certificates. The object of trust would have been the evidence chain, not the brand name on the signature. Inference, moderate: the choice of a real vendor certificate was not incidental. It was the minimum identity needed to sit on a locked-down industrial Windows host. Judgment: a product-assurance regime that treats “signed by a known vendor” as a terminal state, rather than as a claim to be watched, has already accepted the failure class that July made public. Unknown: whether Realtek’s internal controls, VeriSign’s issuance process, or a third-party signing path was the first break. The July file names the Passport. It does not yet name the thief. ## 4. Last-Hop Move and a Possible Act Surface Industrial engineering hosts are often described as air-gapped, as if the absence of an inbound network path were the same thing as the absence of a Move. July’s public story is that the gap was crossed by a removable drive. Microsoft’s own July 16 characterization — most likely exploited through removable drives, limited and targeted — is the vendor’s contemporaneous class, not a later architecture lecture. Siemens’s advisory said the same class in operational language: the program spread via USB sticks; viewing the contents could activate it; customers should avoid USB sticks and check WinCC installations.10 The last hop is therefore a physical Move. A contractor laptop, a programming device, or an engineering workstation that mounts removable media is a path onto a host that was not supposed to have one. This paper will not describe shortcut handling, icon loading, or Autorun alternatives. Those methods sit in the primaries; citing the page is enough. The assurance claim needs only the class: removable media as the last hop toward a possible Act surface. WinCC is that surface in the July file, not yet a proven actuator. Boldewin’s sentence is the first public targeting claim. Siemens raised the scope to WinCC and PCS 7. Krampe’s quotes are customer-warning language, not a plant-damage report. McMillan recorded that some industrial-security specialists read the early analysis as espionage or intellectual-property harvest, and that others called the code “weaponized” in a colloquial sense. Those are contemporaneous judgments. They are not a Siemens statement that a programmable logic controller was altered.11 Sense, Move, and Act therefore separate. Sense, in July, is the public discovery chain: VirusBlokAda’s June 17 find, Krebs on 15 July, Microsoft on 16 July, Siemens’s mid-July customer warning. Move is the removable drive, named by all three institutional voices. Act is the open question. WinCC is a possible Act surface because it is the software that operators use to see and change an industrial process. A host that runs WinCC is not itself a valve or a motor. It is the window onto those things. An implant that seeks that window has reached the last software hop before process change. Whether it then changed a process, in July’s public file, is Unknown. The temptation is to fill the unknown with later memory. The November 2010 Symantec dossier, used here as a compilation of July industry dates and not as a July targeting brief, would later argue that the implant’s final goal was to reprogram industrial control systems. That claim is a later analytic object, not a 15–19 July public Fact. IAEA statements, Iranian centrifuge statements, and any Natanz attribution sit further outside this collection window and are left Unknown.12 A Lab disposition that would have moved the Act question is a Siemens or asset-owner statement, dated in July, that named product versions and said whether controllers — not only WinCC personal computers — had been altered. That statement was not fetched as a July primary. Opportunity is not the same as a negative finding. The honest line is: possible Act surface, named; physical Act, not established; not established is not safe. ## 5. Revocation as a Partial Passport Response The mid-July identity story did not stop at Realtek. Symantec’s *W32.Stuxnet Dossier*, version 1.3, November 2010, compiled the firm’s own July work into a dated timeline. This paper treats that timeline as a primary compilation of July events, not as a July-dated publication. The compilation is November; the events are July. Symantec’s Table 1 records the following July sequence. On 13 July, Symantec added detection as W32.Temphid. On 16 July, Microsoft issued the Windows Shell advisory and VeriSign revoked the Realtek Semiconductor certificate. On 17 July, ESET identified a new driver signed with a JMicron Technology Corp. certificate. On 19 July, Siemens reported that it was investigating malware infecting Siemens WinCC SCADA systems, and Symantec renamed detection to W32.Stuxnet. On 20 July, Symantec began monitoring command-and-control traffic. On 22 July, VeriSign revoked the JMicron certificate.13 Those dates are Facts about what Symantec later said had happened in July. They are high-confidence as a sequence of industry and certificate-authority actions. They are not a finding that this paper independently inspected VeriSign’s revocation logs. They are not a reconstruction of command-and-control tradecraft. The 20 July monitoring line is used here only for the inference the source brief already drew: some infected hosts still had outbound paths. Content of those paths, addresses, and update mechanisms are not described. Two stolen or abused code-signing Passports, then a named industrial vendor, make the event a supply-chain and industrial-control event rather than a generic worm story. After Realtek’s signature was revoked, a JMicron-signed driver appeared in the public investigation within a day. Revocation of the first Passport did not exhaust the identity supply. Neither revocation, as a matter of public-key design, uninstalls a driver already on a disk. A revocation list tells a later verifier not to trust new uses of the certificate. It does not delete a file accepted last month. Inference, moderate: certificate revocation is a partial Passport response. It is the correct issuer action and an incomplete host action. Judgment: a product-assurance regime that treats revocation as remediation has confused the directory with the installed base. The Passport that matters after 16 July is not only “was the certificate revoked.” It is “which hosts already loaded the signed driver, and what evidence would show that the binary is gone.” Unknown: the number of already-infected WinCC hosts in July, the product versions in scope, and whether any programmable logic controller was modified. Siemens’s July advisory promised a removal solution and an analysis of antivirus effects on runtime. It did not, in the fetched text, publish those version tables. The rename to W32.Stuxnet on 19 July is a naming Fact, not an attribution Fact. By that date the antivirus industry and Siemens were treating the family as a WinCC-relevant threat with a public name. The name is useful as a filing handle. It is not a license to import November’s targeting thesis into July’s ledger. ## 6. The Diary as the Same Class of Failure On 25 July 2010 at 5:00 p.m. Eastern, WikiLeaks released the Afghan War Diary. The organization’s own release page is the primary. It called the set “an extraordinary compendium of over 91,000 reports covering the war in Afghanistan from 2004 to 2010.” The reports were written by soldiers and intelligence officers and mainly described lethal United States military actions; they also included intelligence information, reports of meetings with political figures, and related details. About 15,000 reports were withheld for harm minimization, with a promise of later review and eventual release as the security situation permitted. Coverage excluded most United States Special Forces activity, top-secret operations, and most European and other International Security Assistance Force operations. Formats included HTML, CSV, SQL, and KML.14 Those sentences are Facts about what WikiLeaks published as the scope of its own dump. They are not a Department of Defense authenticity statement. They are not a finished audit of any subset. They are not a UAV-strike tally. The source brief’s integrity rule, which this paper keeps, is that this collection did not independently tabulate UAV-tagged rows. Where individual reports mention unmanned aircraft, they become public documentation of UAV use. Inventing a drone-kill count from the dump without a contemporaneous counted primary would be the error the brief forbade. The diary is a Control Fabric leak of the Army’s own Sense-and-report system. Significant Activities and related intelligence notes are the internals of lethal Act: who was sensed, what was reported, what was done, and how the institution filed the event. Operators had assumed those internals would remain inside the fabric. The leak does not prove that every row is accurate. It proves that the assumption of invisibility failed. That is the same type of trust the industrial story punctured the same month. One fabric treated a vendor signature as unseen infrastructure. The other treated field records of killing as unseen infrastructure. Different sources, same class: the public was not supposed to see the internals of Act. Inference, moderate: researchers would mine the diary for civilian-casualty and intelligence-surveillance-reconnaissance patterns, including unmanned mentions. That inference is about subsequent use, not about a July count. Judgment: a Watch desk that treats the dump as a finished UAV study has already lost the reservoir. The correct handling is to grade individual rows, record the stated exclusions (most Special Forces, top secret, most ISAF), and leave the uncounted UAV subset Unknown. Unknown is not a finding that unmanned aircraft are absent from the files. It is a finding that this paper did not count them. A Department of Defense authenticity statement and a public UAV-filtered extract would have reduced reliance on third-party counts. Neither was fetched as a July primary that closes the subset. Opportunity, again, is not a negative. ## 7. What July Did Not Prove Analytic honesty is the method, not a disclaimer at the end. The month is famous for what later readers think they already know. The opened file is thinner, and the thinness is the point. Physical plant consequence is not proven in the July public sources fetched here. Krebs, Microsoft, and Siemens establish a signed implant, a removable-media last hop, and a WinCC-relevant investigation. They do not establish a changed controller, a damaged process, or a named facility. Boldewin’s “espionage” sentence and the colloquial “weaponized” language in *Computerworld* are contemporaneous judgments, not plant telemetry. The November dossier’s later claim that the implant’s goal was to reprogram industrial control systems is a later object. It is cited-via-secondary as a November compilation and is not promoted to a July Fact. IAEA or Iranian statements linking centrifuge trouble to malware do not exist in this collection window. They are left Unknown. Later-memory attribution to a named enrichment site is excluded by the same rule. A Watch desk that imports those statements backward has stopped doing July and started doing memoir. The Afghan War Diary is not a finished UAV-strike tally. WikiLeaks stated a scope, an exclusion set, and a withheld tranche. This paper did not tabulate unmanned rows. Third-party counts that appeared after 25 July are not used. The diary remains a Control Fabric leak of SIGACTs, graded as a reservoir. CRS product RS21698, *Homeland Security: Unmanned Aerial Vehicles and Border Surveillance*, by Chad C. Haddal and Jeremiah Gertler, is dated 8 July 2010. The congress.gov product page was not retrieved as a document body. Bibliographic facts were confirmed from the EveryCRSReport HTML reprint, which this paper retrieved. Internal tables are not used. The report is indexed as a same-month congressional Sense object, not as a third thesis.15 July strike-level Facts for the extra-theater UAV campaign were not fetched. Continuity of that campaign is a moderate inference from the absence of a July official ending and from the last detailed official-adjacent snapshot in this collection, which remains January 2010. Counts for July are Unknown. These gaps are not a reason to soften the Passport claim. They are a reason to keep it narrow. The signature was accepted. The last hop was a stick. The possible Act surface was named. The field archive left the fabric. What the implant did to a plant, and what the diary would yield if counted for unmanned rows, are later questions. They are not July closures. ## 8. Extra-Theater Act Was Not Paused Public attention in July went to malware and WikiLeaks. The remote-kill program continued as a separate Act ledger. No July official United States statement ending the Pakistan drone campaign was fetched. The last detailed official-adjacent snapshot in this collection remains Scott Shane and Eric Schmitt’s 23 January 2010 account, via NBC News from *The New York Times*: Virginia satellite control, a Pakistan launch base, expected Reaper growth, and a CIA spokesman’s line that counterterrorism operations “continue without pause.”16 That January plate is continuity, not a July order of battle. It is cited here as a one-clause pointer, not as a rebuilt Pakistan campaign. Sibling papers already occupy that ground: January 2009 as inherited covert air-unmanned command and control, October 2001 as the first combat Hellfire and the split among CIA, the Air Force, and Central Command, and May 2011 as a U.S.-citizen target under mixed attribution in Yemen. This paper does not reopen those arguments. Kestrel’s proper use in a July 2010 Watch file is to keep Waziristan on the board while the new public stories run, not to decorate Stuxnet or the diary with a strike tally this collection does not have. ## 9. What a July Passport Would Have Recorded The durable lesson is not that industrial software can be reached, or that armies keep records. Both were already known. The lesson is that identity and invisibility were doing work that the operators had stopped seeing as work. A July Passport on a WinCC host would have been an evidence chain, not a seal. It would have recorded the signer of each kernel driver, the certificate issuer and serial, the first-seen timestamp, the revocation-check result, and the human who accepted the binary. It would have recorded removable media as a last-hop Move and WinCC or PCS 7 as a possible Act surface, with product version and whether the host could reach a controller. It would not have published a how-to or certified the plant as safe. It would have made the next revocation a host question: which installed drivers still matched a now-revoked certificate, and what disposition closed them. The same logic applies to the diary, with the objects renamed. A Control Fabric that files lethal Act should assume that the archive can leave the building. Withholding 15,000 reports for harm minimization is itself evidence that someone inside the leak path understood the assumption was failing. A Passport on a SIGACT system is a graded record of who may export and what is withheld, not a finished UAV study. LrrK’s Lab earns a place only as the disposition that would have moved July’s unknowns: a Siemens customer advisory that named controller versions and said whether process logic had been altered; a Department of Defense authenticity statement and a UAV-filtered extract; a certificate-authority audit after the Realtek and JMicron revocations that distinguished stolen tokens from abused signing services. None of those dispositions is in the fetched July file. KAT, as a later structured-assurance test, would have asked a narrower question than “was this Stuxnet”: did the host still trust a revoked industrial-adjacent signer, and did removable media remain an unlogged last hop. Those are software-assurance questions. They do not require a reproduction of the implant. Campaign is the object this paper mostly refuses. July is not a single campaign. It is a month in which two fabrics lost the bet that Act internals would stay unseen. Watch’s job is to keep the plates separate and the unknowns labeled. Kestrel correlates the next named pair; it does not invent a July strike table to keep the industrial story company. ## 10. Conclusion July 2010 is the month a signed driver and a war diary became public for the same reason. Operators had assumed the internals of Act would stay unseen. On the industrial side, Windows treated a vendor signature as a Passport, a removable drive was a sufficient last-hop Move, and Siemens WinCC was named as a possible Act surface before anyone in the fetched public file had proved a changed plant. On the military side, more than ninety thousand field reports of lethal action, plus intelligence and political-meeting notes, left the Army’s own Sense-and-report system, with a stated exclusion set and a withheld tranche. The sources are different. The trust class is not. Certificate revocation was the correct issuer response and an incomplete host response. It closed future uses of two certificates. It did not uninstall drivers already accepted. A product-assurance regime that stops at the revocation list has confused the directory with the installed base. A journalism regime that treats the diary as a finished unmanned-kill study has confused a reservoir with a count. Both errors are versions of the same haste: filling July with what the reader now thinks the month must have meant. The honest unit of analysis is the Passport. The signature was the identity the implant needed. The stick was the Move the air gap still allowed. The possible Act surface was an industrial window that operators had not been prepared to see in a newspaper. The diary was a lethal-action archive that operators had not been prepared to see in a spreadsheet. Later memory would add plants, centrifuges, and tallies. Those additions are excluded here because they were not July public record in this collection. The unknowns remain labeled. They are not safe. Endnotes 1. The research premise and the integrity limits (no exploit recipe, no later-memory Iran-centrifuge attribution, no independently tabulated UAV count from the diary) follow the July 2010 LrrK Kinematic Threat Brief, “2010-07-kinematic-threat-brief.md,” collection cutoff 31 July 2010, Drive file id 12GWnyx5YonBSbxc54yik7p3f4jygtGYW. https://drive.google.com/file/d/12GWnyx5YonBSbxc54yik7p3f4jygtGYW/view?usp=drivesdk 2. Brian Krebs, “Experts Warn of New Windows Shortcut Flaw,” Krebs on Security, 15 July 2010, updated 16 July 2010. https://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw/ 3. Ibid. 4. Microsoft, “Microsoft Security Advisory 2286198: Vulnerability in Windows Shell Could Allow Remote Code Execution,” published 16 July 2010, updated 2 August 2010. https://learn.microsoft.com/en-us/security-updates/securityadvisories/2010/2286198 5. Dave Forstrom, “Security Advisory 2286198 Released,” Microsoft Security Response Center, 16 July 2010. https://www.microsoft.com/en-us/msrc/blog/2010/07/security-advisory-2286198-released 6. Siemens, “Update on Virus Affecting Simatic WinCC SCADA Systems,” media advisory as reprinted by *Control Global*. https://www.controlglobal.com/home/blog/11344301/siemens-media-advisory-regarding-the-virus-affecting-simatic-wincc-scada-systems 7. Robert McMillan, “New virus targets industrial secrets,” *Computerworld*, 17 July 2010. https://www.computerworld.com/article/1509083/new-virus-targets-industrial-secrets.html 8. Microsoft, “Microsoft Security Bulletin MS10-046 - Critical: Vulnerability in Windows Shell Could Allow Remote Code Execution (2286198),” 2 August 2010, Acknowledgments. Cited as an August credit record, not as a July event. https://learn.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-046. VirusBlokAda’s own English page at https://anti-virus.by/en/tempo.shtml was requested and returned HTTP 404; it is not cited as retrieved. 9. Krebs, “Experts Warn of New Windows Shortcut Flaw”; McMillan, “New virus targets industrial secrets.” 10. Forstrom, “Security Advisory 2286198 Released”; Siemens media advisory as reprinted by *Control Global*. 11. Krebs, “Experts Warn of New Windows Shortcut Flaw”; Siemens media advisory as reprinted by *Control Global*; McMillan, “New virus targets industrial secrets.” 12. Nicolas Falliere, Liam O Murchu, and Eric Chien, *W32.Stuxnet Dossier*, Version 1.3, Symantec Security Response, November 2010. Used here as a November compilation of July industry dates (Table 1, p. 4). Later-memory targeting claims in the same paper’s executive summary are not promoted to July Facts. https://www.cs.unh.edu/~it666/reading_list/ZeroDay/w32_stuxnet_dossier.pdf 13. Ibid., Table 1, p. 4. 14. WikiLeaks, “Afghan War Diary, 2004-2010,” release page, 25 July 2010, 5:00 p.m. EST. https://www.wikileaks.org/wiki/Afghan_War_Diary,_2004-2010 15. Chad C. Haddal and Jeremiah Gertler, *Homeland Security: Unmanned Aerial Vehicles and Border Surveillance*, CRS Report RS21698, 8 July 2010. Bibliographic Fact (title, authors, product number, date) confirmed from the EveryCRSReport HTML reprint; congress.gov product page was not retrieved as a document body. Internal tables are not quoted. https://www.everycrsreport.com/reports/RS21698.html. Named congress.gov locator, not retrieved as body: https://www.congress.gov/crs-product/RS21698 16. Scott Shane and Eric Schmitt, “C.I.A. deaths prompt surge in U.S. drone strikes,” *The New York Times*, via NBC News, 23 January 2010. https://www.nbcnews.com/id/wbna35027603 Selected Bibliography Falliere, Nicolas, Liam O Murchu, and Eric Chien. *W32.Stuxnet Dossier*. Version 1.3. Symantec Security Response, November 2010. https://www.cs.unh.edu/~it666/reading_list/ZeroDay/w32_stuxnet_dossier.pdf Forstrom, Dave. “Security Advisory 2286198 Released.” Microsoft Security Response Center, 16 July 2010. https://www.microsoft.com/en-us/msrc/blog/2010/07/security-advisory-2286198-released Haddal, Chad C., and Jeremiah Gertler. *Homeland Security: Unmanned Aerial Vehicles and Border Surveillance*. CRS Report RS21698, 8 July 2010. EveryCRSReport HTML reprint. https://www.everycrsreport.com/reports/RS21698.html Krebs, Brian. “Experts Warn of New Windows Shortcut Flaw.” Krebs on Security, 15 July 2010, updated 16 July 2010. https://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw/ McMillan, Robert. “New virus targets industrial secrets.” *Computerworld*, 17 July 2010. https://www.computerworld.com/article/1509083/new-virus-targets-industrial-secrets.html Microsoft. “Microsoft Security Advisory 2286198: Vulnerability in Windows Shell Could Allow Remote Code Execution.” 16 July 2010, updated 2 August 2010. https://learn.microsoft.com/en-us/security-updates/securityadvisories/2010/2286198 Microsoft. “Microsoft Security Bulletin MS10-046 - Critical.” 2 August 2010. https://learn.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-046 Shane, Scott, and Eric Schmitt. “C.I.A. deaths prompt surge in U.S. drone strikes.” *The New York Times*, via NBC News, 23 January 2010. https://www.nbcnews.com/id/wbna35027603 Siemens. “Update on Virus Affecting Simatic WinCC SCADA Systems.” Media advisory as reprinted by *Control Global*. https://www.controlglobal.com/home/blog/11344301/siemens-media-advisory-regarding-the-virus-affecting-simatic-wincc-scada-systems WikiLeaks. “Afghan War Diary, 2004-2010.” 25 July 2010. https://www.wikileaks.org/wiki/Afghan_War_Diary,_2004-2010 Source note. This paper distinguishes July 2010 public discovery (Krebs, Microsoft Advisory 2286198, Siemens’s mid-July customer warning) from Symantec’s November 2010 compilation of July industry dates, and it distinguishes both from later-memory Iran, centrifuge, and Natanz attribution, which is excluded. The Afghan War Diary is treated as a Control Fabric leak of SIGACTs on WikiLeaks’s own stated scope, not as a UAV-strike tally; this collection did not independently tabulate UAV-tagged rows. CRS RS21698 is cited for bibliographic Fact from an HTML reprint after the congress.gov product page failed to return a document body; internal tables are not used. VirusBlokAda’s own English page was requested and was not retrieved. Extra-theater UAV Act is noted as continuity from the January Shane/Schmitt snapshot only; the Pakistan campaign is not rebuilt. No exploit recipe, payload-frequency table, shortcut-handling procedure, removable-media infection method, or command-and-control tradecraft is included. The analysis is current as of 19 August 2026 and should be revalidated against any subsequent official Siemens July customer advisory that names controller versions, any Department of Defense authenticity statement on the diary, and any certificate-authority audit of the Realtek and JMicron revocations.