Solar Winds Blow Hard

Unbelievable! But true. The enormous hack, purportedly by Russia (per Secretary of State Mike Pompeo and others), of major U.S. government agencies and the U.S.’s biggest corporations—apparently some 18,000 organizations according to the software maker… Continue reading Solar Winds Blow Hard

Two groups might have breached SolarWinds Orion software- Microsoft

By Deeba Ahmed
The ongoing investigation into the SolarWinds supply chain cyberattack indicates the involvement of another APT group.
This is a post from HackRead.com Read the original post: Two groups might have breached SolarWinds Orion software- Mic… Continue reading Two groups might have breached SolarWinds Orion software- Microsoft

SolarWinds/SUNBURST Backdoor, Third-Party and Supply Chain Security

In episode 152 for December 21st 2020: A discussion about the SolarWinds Orion backdoor, third-party security, and the threat of supply chain attacks with co-host Kevin Johnson. ** Links mentioned on the show ** US govt, FireEye breached after SolarWin… Continue reading SolarWinds/SUNBURST Backdoor, Third-Party and Supply Chain Security

Microsoft Caught Up in SolarWinds Spy Effort, Joining Federal Agencies

The ongoing, growing campaign is “effectively an attack on the United States and its government and other critical institutions,” Microsoft warned. Continue reading Microsoft Caught Up in SolarWinds Spy Effort, Joining Federal Agencies

Nuclear Weapons Agency Hacked in Widening Cyberattack – Report

Sources said the DoE suffered “damage” in the attack, which also likely extends beyond the initially known SolarWinds Orion attack vector. Continue reading Nuclear Weapons Agency Hacked in Widening Cyberattack – Report

Malicious Domain in SolarWinds Hack Turned into ‘Killswitch’

A key malicious domain name used to control potentially thousands of computer systems compromised via the months-long breach at network monitoring software vendor SolarWinds was commandeered by security experts and used as a “killswitch” designed to turn the sprawling cybercrime operation against itself, KrebsOnSecurity has learned. Continue reading Malicious Domain in SolarWinds Hack Turned into ‘Killswitch’

Finding SUNBURST Backdoor with Zeek Logs & Corelight

John Gamble, Director of Product Marketing, Corelight FireEye’s threat research team has discovered a troubling new supply chain attack targeting SolarWind’s Orion IT monitoring and management platform. The attack trojanizes Orion software updates to d… Continue reading Finding SUNBURST Backdoor with Zeek Logs & Corelight

DHS Among Those Hit in Sophisticated Cyberattack by Foreign Adversaries – Report

The attack was mounted via SolarWinds Orion, in a manual and targeted supply-chain effort. Continue reading DHS Among Those Hit in Sophisticated Cyberattack by Foreign Adversaries – Report

U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise

Communications at the U.S. Treasury and Commerce Departments were reportedly compromised by a supply chain attack on SolarWinds, a security vendor that helps the federal government and a range of Fortune 500 companies monitor the health of their IT networks. Given the breadth of the company’s customer base, experts say the incident may be just the first of many such disclosures. Continue reading U.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise