The Wall Street Journal identified 24 businesses so far that have downloaded the SolarWinds software infected with malicious code.
A new Wall Street Journal analysis began to name some of the organizations affected in a major cyber-espionage campaign conducted by suspected Russian nation-state attackers. The victims include major US technology and accounting firms, a university, and at least one hospital.
Companies affected include Cisco, Intel, Nvidia, VMware, Deloitte, and Belkin International, in addition to California Department of State Hospitals and Kent State University, the WSJ found. Analysis revealed infected machines at 24 organizations that downloaded infected versions of SolarWinds Orion network management software, which had a backdoor installed in a routine update.
Cisco detected the malicious software on some employee systems and lab systems; so far, it says there is no effect on its products or services. Intel is investigating and has said there is no indication attackers accessed its network. Similarly, the other organizations affected confirm they detected the infected software but there is no indication attackers have exploited it.
The 24 companies identified here mark just a small number of the some 18,000 organizations that may have been affected in the massive supply chain attack, news of which broke last week.
Read the full WSJ analysis here.
About the Author(s)
You May Also Like
Securing Code in the Age of AI
April 24, 2024Beyond Spam Filters and Firewalls: Preventing Business Email Compromises in the Modern Enterprise
April 30, 2024Key Findings from the State of AppSec Report 2024
May 7, 2024Is AI Identifying Threats to Your Network?
May 14, 2024Where and Why Threat Intelligence Makes Sense for Your Enterprise Security Strategy
May 15, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024