{
  "version": 1,
  "event_id": "evt_9ac8e4c2aaabe3f9",
  "url": "https://xiyu.news/events/evt_9ac8e4c2aaabe3f9/",
  "json": "https://xiyu.news/api/events/evt_9ac8e4c2aaabe3f9.json",
  "type": "security_incident",
  "status": "monitoring",
  "category": "technology",
  "title": {
    "zh": "黑客新闻用户重构震网网络武器源代码",
    "en": "Hacker News User Reconstructs Stuxnet Cyber-Weapon Source Code"
  },
  "current_state": {
    "zh": "一位黑客新闻（Hacker News）用户发布了震网（Stuxnet）恶意软件的重构源代码，声称仅供研究和教育使用。该项目于GitHub上公开，可在Windows XP和Windows 7上运行，复现了2010年被发现的这款网络武器的代码。\n\n震网被广泛认为是全球首款能够造成物理破坏的数字武器，据报道曾摧毁伊朗近五分之一的核离心机。公开其重构源代码有助于历史和技术教育，但也引发了双重用途的担忧，即可能让攻击者研究真实的攻击性网络能力。\n\n根据讨论区评论，这段重构代码约有15,000行，针对与原始震网相同的目标：西门子S7 PLC和WINCC HMI系统。仓库声明其仅在Windows XP和Windows 7上运行。",
    "en": "A Hacker News user posted a reconstructed source code of the Stuxnet malware on GitHub, claiming it is for research and educational use only. The project, which runs on Windows XP and Windows 7, reproduces the code of the cyber-weapon that was discovered in 2010.\n\nStuxnet is widely regarded as the world's first digital weapon to cause physical destruction, having reportedly ruined nearly one-fifth of Iran's nuclear centrifuges. Making a reconstructed version accessible supports historical and technical education, but also raises dual-use concerns about enabling attackers to study a real offensive cyber-capability.\n\nAccording to a comment in the discussion, the reconstructed code spans roughly 15,000 lines and is based on the same target as the original Stuxnet: Siemens S7 PLCs and WINCC HMI systems. The repository explicitly states it works only on Windows XP and Windows 7."
  },
  "first_seen_at": "2026-09-08T04:10:55.024836+00:00",
  "last_updated_at": "2026-09-08T04:10:55.024836+00:00",
  "last_material_change_at": "2026-09-08T04:10:55.024836+00:00",
  "confidence": 0.75,
  "updates_count": 1,
  "sources_count": 1,
  "entities": [
    "code",
    "cyber",
    "hacker",
    "hackernews",
    "news",
    "reconstructs",
    "source",
    "source-code",
    "stuxnet",
    "user",
    "weapon"
  ],
  "identifiers": [],
  "topics": [
    "critical-infrastructure",
    "cybersecurity",
    "hackernews",
    "source-code",
    "stuxnet"
  ],
  "updates": [
    {
      "update_id": "upd_b3c119bcd928d07c",
      "event_id": "evt_9ac8e4c2aaabe3f9",
      "occurred_at": "2026-09-07T22:12:38Z",
      "published_at": "2026-09-07T22:12:38Z",
      "first_seen_at": "2026-09-08T04:10:55.024836Z",
      "time_precision": "published",
      "update_type": "initial",
      "material_change": true,
      "title_zh": "黑客新闻用户重构震网网络武器源代码",
      "title_en": "Hacker News User Reconstructs Stuxnet Cyber-Weapon Source Code",
      "what_changed_zh": "一位黑客新闻（Hacker News）用户发布了震网（Stuxnet）恶意软件的重构源代码，声称仅供研究和教育使用。该项目于GitHub上公开，可在Windows XP和Windows 7上运行，复现了2010年被发现的这款网络武器的代码。\n\n震网被广泛认为是全球首款能够造成物理破坏的数字武器，据报道曾摧毁伊朗近五分之一的核离心机。公开其重构源代码有助于历史和技术教育，但也引发了双重用途的担忧，即可能让攻击者研究真实的攻击性网络能力。\n\n根据讨论区评论，这段重构代码约有15,000行，针对与原始震网相同的目标：西门子S7 PLC和WINCC HMI系统。仓库声明其仅在Windows XP和Windows 7上运行。",
      "what_changed_en": "A Hacker News user posted a reconstructed source code of the Stuxnet malware on GitHub, claiming it is for research and educational use only. The project, which runs on Windows XP and Windows 7, reproduces the code of the cyber-weapon that was discovered in 2010.\n\nStuxnet is widely regarded as the world's first digital weapon to cause physical destruction, having reportedly ruined nearly one-fifth of Iran's nuclear centrifuges. Making a reconstructed version accessible supports historical and technical education, but also raises dual-use concerns about enabling attackers to study a real offensive cyber-capability.\n\nAccording to a comment in the discussion, the reconstructed code spans roughly 15,000 lines and is based on the same target as the original Stuxnet: Siemens S7 PLCs and WINCC HMI systems. The repository explicitly states it works only on Windows XP and Windows 7.",
      "current_state_zh": "一位黑客新闻（Hacker News）用户发布了震网（Stuxnet）恶意软件的重构源代码，声称仅供研究和教育使用。该项目于GitHub上公开，可在Windows XP和Windows 7上运行，复现了2010年被发现的这款网络武器的代码。\n\n震网被广泛认为是全球首款能够造成物理破坏的数字武器，据报道曾摧毁伊朗近五分之一的核离心机。公开其重构源代码有助于历史和技术教育，但也引发了双重用途的担忧，即可能让攻击者研究真实的攻击性网络能力。\n\n根据讨论区评论，这段重构代码约有15,000行，针对与原始震网相同的目标：西门子S7 PLC和WINCC HMI系统。仓库声明其仅在Windows XP和Windows 7上运行。",
      "current_state_en": "A Hacker News user posted a reconstructed source code of the Stuxnet malware on GitHub, claiming it is for research and educational use only. The project, which runs on Windows XP and Windows 7, reproduces the code of the cyber-weapon that was discovered in 2010.\n\nStuxnet is widely regarded as the world's first digital weapon to cause physical destruction, having reportedly ruined nearly one-fifth of Iran's nuclear centrifuges. Making a reconstructed version accessible supports historical and technical education, but also raises dual-use concerns about enabling attackers to study a real offensive cyber-capability.\n\nAccording to a comment in the discussion, the reconstructed code spans roughly 15,000 lines and is based on the same target as the original Stuxnet: Siemens S7 PLCs and WINCC HMI systems. The repository explicitly states it works only on Windows XP and Windows 7.",
      "detailed_summary_zh": "一位黑客新闻（Hacker News）用户发布了震网（Stuxnet）恶意软件的重构源代码，声称仅供研究和教育使用。该项目于GitHub上公开，可在Windows XP和Windows 7上运行，复现了2010年被发现的这款网络武器的代码。\n\n震网被广泛认为是全球首款能够造成物理破坏的数字武器，据报道曾摧毁伊朗近五分之一的核离心机。公开其重构源代码有助于历史和技术教育，但也引发了双重用途的担忧，即可能让攻击者研究真实的攻击性网络能力。\n\n根据讨论区评论，这段重构代码约有15,000行，针对与原始震网相同的目标：西门子S7 PLC和WINCC HMI系统。仓库声明其仅在Windows XP和Windows 7上运行。",
      "detailed_summary_en": "A Hacker News user posted a reconstructed source code of the Stuxnet malware on GitHub, claiming it is for research and educational use only. The project, which runs on Windows XP and Windows 7, reproduces the code of the cyber-weapon that was discovered in 2010.\n\nStuxnet is widely regarded as the world's first digital weapon to cause physical destruction, having reportedly ruined nearly one-fifth of Iran's nuclear centrifuges. Making a reconstructed version accessible supports historical and technical education, but also raises dual-use concerns about enabling attackers to study a real offensive cyber-capability.\n\nAccording to a comment in the discussion, the reconstructed code spans roughly 15,000 lines and is based on the same target as the original Stuxnet: Siemens S7 PLCs and WINCC HMI systems. The repository explicitly states it works only on Windows XP and Windows 7.",
      "background_zh": "震网是2010年被公开发现的著名计算机蠕虫，由美国情报机构联合以色列情报部门于2000年代中期开发。它利用U盘等方式突破物理隔离，攻击了伊朗纳坦兹铀浓缩工厂的西门子工业控制设备，通过篡改离心机转速造成其物理损毁。这证明了恶意软件能够从数字领域跨越到物理世界，对关键基础设施构成直接威胁。",
      "background_en": "Stuxnet is a notorious computer worm discovered in 2010, created by U.S. and Israeli intelligence agencies in the mid-2000s. It crossed the air gap to attack Siemens industrial control equipment at Iran's Natanz uranium enrichment facility, manipulating centrifuge speeds to physically destroy them. This demonstrated how malware could move from the digital realm into the physical world, posing a direct threat to critical infrastructure.",
      "community_discussion_zh": "评论者总体上对该帖表示赞赏，一位用户提到约1.5万行代码提供了大量可供审阅的内容，并推荐了《Countdown to Zero Day》一书。还有人质疑U盘传播途径的可行性，并猜测受感染的硬件是否可能来自不规范的经销商。讨论整体偏向技术性且态度正面，包括一个关于离心机销毁计数器的代码玩笑。",
      "community_discussion_en": "Commenters largely appreciated the post, with one user noting the roughly 15,000 lines give plenty to examine and recommending the book \"Countdown to Zero Day.\" Another raised a question about the feasibility of USB-drive propagation and whether infected hardware may have come from resellers. The tone was technical and positive, including a playful code joke referencing the centrifuge-destruction counter.",
      "market_impact_zh": "震网重构源代码的公开可能会促使企业和政府重新关注OT/ICS安全，进而可能推动对工业网络安全防护的投入。目前并没有明显的直接加密资产传导渠道；若产生影响，也将是通过网络安全板块与整体风险偏好的间接传导。",
      "market_impact_en": "Public availability of a Stuxnet reconstruction could renew organizational and governmental focus on OT/ICS security, potentially supporting spending on industrial cybersecurity defenses. No direct crypto-asset transmission channel is apparent; impact, if any, would be indirect through the cybersecurity sector and broader risk sentiment.",
      "importance_score": 7.5,
      "references": [
        {
          "url": "https://en.wikipedia.org/wiki/Stuxnet",
          "title": "Stuxnet - Wikipedia"
        },
        {
          "url": "https://github.com/Sadpainy/Stuxnet?ref=upstract.com",
          "title": "GitHub - Sadpainy/Stuxnet at upstract.com · GitHub"
        },
        {
          "url": "https://news.ycombinator.com/item?id=49603546",
          "title": "Show HN: Stuxnet – A reconstructed source code of... | Hacker News"
        },
        {
          "url": "https://github.com/Sadpainy/Stuxnet",
          "title": "GitHub - Sadpainy/Stuxnet: Stuxnet, Here reproduced by me, Only for ..."
        },
        {
          "url": "https://zeli.app/story/49603546",
          "title": "Stuxnet - Educational reconstruction · Hacker News | Zeli"
        }
      ],
      "confidence": 0.75,
      "story_ids": [
        "hackernews:story:49603546"
      ],
      "sources": [
        {
          "url": "https://github.com/Sadpainy/Stuxnet",
          "label": "CMDDestory",
          "source_type": "hackernews",
          "official": false
        }
      ]
    }
  ]
}
