7 Things We Know So Far About the SolarWinds Attacks
Two months after the news first broke, many questions remain about the sophisticated cyber-espionage campaign.
February 11, 2021
Nearly two months after news surfaced about software updates from SolarWinds being used to distribute a backdoor Trojan called Sunburst/Solorigate to some 18,000 organizations worldwide, troubling questions remain about the scope and impact of the breach.
The campaign, which the US government and others have described as a highly sophisticated espionage operation by a Russia-backed group, has raised broad fears of sensitive data being stolen from several US government agencies and large companies.
In addition, there are considerable fears that the attackers may have gained deep, persistent, and almost undetectable access on networks belonging to numerous organizations in sectors including manufacturing, industrial, construction, and logistics. Some believe it will take months for victims to ensure they have truly eradicated the threat from their networks.
The incident has resurfaced old concerns over supply chain vulnerabilities and some new ones over the ability of even the best security tools and controls to detect highly targeted attacks. The fact that some of the campaign's victims include top technology firms such as Microsoft and security vendors like FireEye has not helped.
On Tuesday, concerns over the breach prompted members of the US Senate Intelligence Committee to send a letter to leaders of the intelligence community asking for a more coordinated response at the federal level. The letter, signed by Sens. Mark Werner (D-Va.) and Marco Rubio (R-Fla.), expressed concern over the "disjointed and disorganized" US response to the incident so far and called for the appointment of a "clear leader" to head the effort going forward.
"The threat our country still faces from this incident needs clear leadership to develop and guide a unified strategy for recovery," the two lawmakers wrote, noting the fact that numerous federal agencies and thousands of private-sector entities had been impacted.
Here is a recap of what is known — and unknown — about the campaign to date.
About the Author
You May Also Like
Unleashing AI to Assess Cyber Security Risk
Nov 12, 2024Securing Tomorrow, Today: How to Navigate Zero Trust
Nov 13, 2024The State of Attack Surface Management (ASM), Featuring Forrester
Nov 15, 2024Applying the Principle of Least Privilege to the Cloud
Nov 18, 2024The Right Way to Use Artificial Intelligence and Machine Learning in Incident Response
Nov 20, 2024