
The Cyberweapons Arms Race
Nicole Perlroth · 2021 · Technology
Original summary · AI-drafted, human-published · added by Library
Nicole Perlroth, a New York Times cybersecurity reporter, spent seven years tracing the underground market for 'zero-day' software vulnerabilities: the flaws hackers, brokers, and governments buy and sell before anyone can patch them. She argues the United States built this market to arm itself, then watched the same weapons proliferate to rivals and criminals, leaving critical infrastructure, elections, and hospitals dangerously exposed. The book matters because it documents, with named sources, how offense-first policy created the vulnerability it was meant to prevent.
Pick a finish date and Genius lays out the days — the plan shows today's target and keeps you honest.
Start a circle and share the code — everyone sees everyone's honest place in the book. Accountability, not leaderboards.
- Policy and national security readers who want the real history behind terms like Stuxnet and NotPetya - Technologists and IT professionals who need to understand why patching is a geopolitical problem, not just an engineering one - General readers alarmed by ransomware and infrastructure attacks who want to know how the market that enables them actually works
A functioning black-and-gray market for unpatched software flaws exists because governments, not criminals, created the first sustained demand for them.
Intelligence agencies that stockpile vulnerabilities rather than disclosing them are trading short-term offensive advantage for long-term collective vulnerability.
The 2016-2017 theft and release of NSA hacking tools by a group calling itself the Shadow Brokers proved that no stockpile, however classified, is safe from being turned into a public weapon.
EternalBlue's escape into criminal and state hands in 2017 turned a single leaked exploit into two of the most economically destructive cyberattacks in history, proving that stolen offensive tools cause harm far beyond their original target.
Private firms selling exploits and surveillance tools to any government willing to pay have made offensive cyber capability available to regimes with no restraint on how they use it.
Russian intelligence treated American digital infrastructure and information systems as an active battlefield years before most U.S. officials recognized the threat, using hacking as one tool among many in a broader influence campaign.
American power grids, water systems, and industrial control systems remain vulnerable not because attackers lack capability but because owners of that infrastructure have underinvested in defense for decades.
Meaningful defense against cyberweapons requires international norms and domestic policy change, but neither has kept pace with the speed at which offensive capability has spread.
Nicole Perlroth covered cybersecurity for the New York Times for nearly a decade, breaking stories on state-sponsored hacking, the NSA's tools, and the zero-day trade. She interviewed hundreds of hackers, spies, and officials, often off the record, to reconstruct a market intentionally hidden from public view.