A 2025 report on a botnet infecting more than 9,000 routers caps coverage that repeatedly places Ars Technica reporter Dan Goodin in major cybersecurity disclosures.
The corpus identifies Dan Goodin as an Ars Technica reporter whose coverage footprint is concentrated in cybersecurity: vulnerabilities, malware, breaches, botnets, authentication systems, and the security practices of major technology platforms including Microsoft, Google, Apple, Android, and Linux.
Coverage peaked in 2015Q3, then settled into a more periodic security-news pattern in recent years. The latest cluster is driven by operationally significant threats rather than consumer-tech launches: GreyNoise's report of a persistent SSH backdoor affecting more than 9,000 routers, SentinelLabs' account of AkiraBot using OpenAI's API to generate spam, and research on Linux perfctl malware, Zimbra exploitation, and the Android.Vo1d botnet.
The recurring tension is between public-interest vulnerability reporting and the institutions exposed by it. Keeper Security sued Ars Technica and Goodin over an Ars story describing a vulnerability, a direct example of the legal and reputational pressure that can accompany security reporting; broader coverage also repeatedly follows vendor and researcher disputes, including Apple's criticism of Google's Project Zero disclosure framing.
If the current trajectory holds, Goodin's coverage remains relevant as attacks shift from isolated software flaws toward persistent compromises of routers, email servers, cloud-linked accounts, and widely deployed open-source infrastructure. The corpus suggests the key uncertainty is whether disclosures and enforcement actions can reduce that exposure before threats scale across the interconnected Microsoft, Google, Apple, Android, and Linux ecosystems.
Dan Goodin has appeared in 144 articles since 2015-01. Coverage peaked in 2022Q2 with 4 articles. Frequently mentioned alongside Microsoft, Google, Android, Apple.