SOLARWINDS SUPPLY CHAIN ATTACK

Dec 14, 2020

Hackers, believed to be operating on behalf of the Russian Government, have gained access to software provider SolarWinds. They then deployed an update containing a trojan which created a backdoor to its 'Orion' remote monitoring platform – which has been used to attack networks of multiple US companies and Government networks including the US Treasury. Last week's breach of the cyber security firm – FireEye –  lead to the theft of its penetration testing tools.

It is believed that the attack may have occurred in Spring 2020. In a statement, Solarwinds confirmed that they were “aware of a potential vulnerability which, if present, is currently believed to be related to updates which were released between March and June 2020”.


“This vulnerability is the result of a highly sophisticated, targeted and manual supply chain attack by a nation state. We are acting in close coordination with FireEye, the Federal Bureau of Investigation, the intelligence community, and other law enforcement to investigate these matters. As such, we are limited as to what we can share at this time.”


SolarWinds also said that it plans to release a new update on Tuesday, 15th December that “replaces the compromised component and provides several additional security enhancements.”


"The compromise of SolarWinds’ Orion Network Management Products poses unacceptable risks to the security of federal networks,” said Brandon Wales, acting director of the US Cybersecurity and Infrastructure Security Agency (CISA), which has released an emergency directive, urging federal agencies to review their networks and power down SolarWinds Orion products immediately.

SHARE


19 Feb, 2024
INTEGRITY IT Solutions has strengthened its team following a successful restructuring of the business.
Leading IT specialists Integrity IT Solutions are supporting schools to achieve faster broadband.
19 Jan, 2024
A LEADING IT company is offering schools and colleges a free review of their broadband connectivity to help them achieve targets for faster internet speeds as outlined in the latest Government’s guidelines.
01 Jun, 2023
With ever-increasing pressures on businesses to achieve net zero, Gary Robertson, from EcoGoZero, explains why collaboration is key.
01 Jun, 2023
Stephen Whelan, technical director at Carlisle-based Integrity IT Solutions, on why resolving IT issues will protect your business now and in the future.
01 May, 2023
Stephen Whelan, from Carlisle-based Integrity IT Solutions, talks about the threat from cyber criminals.
SHOW MORE
Share by: