Fireeye, Solarwinds, U.S. Treasury: What's Happening in the Cyber
FireEye, SolarWinds, U.S. Treasury: What’s Happening in the Cyber Security World Right Now? written by Team NetSPI | December 15, 2020 As we write this post, you’ve likely heard about the FireEye and U.S. government agency breaches that occurred over the past week. We know now the breaches have been linked back to a supply chain attack on the SolarWinds Orion Platform, a software platform that manages IT operations and products for over 300,000 organizations, including over 425 of the Fortune 500, all ten of the top U.S. telecommunications companies, all five branches of the U.S. Military, all five of the top U.S. accounting firms, and many, many more. While FireEye, the U.S. Treasury, and National Telecommunications and Information Administration (NTIA) were the first to report a security breach, the breadth of SolarWinds’ customer base is an indicator that the breaches are seemingly the tip of the iceberg. For the sake of information sharing, here is an overview of the attacks, immediate steps you can take to identify whether you have fallen victim, and tips for protecting your organization as communicated by FireEye, SolarWinds, and NetSPI. For the full technical deep-dive, we highly recommend the FireEye blog post. Overview: SolarWinds Orion Manual Supply Chain Attack On December 13, SolarWinds issued a security advisory alerting to a manual supply chain attack on its Orion Platform software builds for versions 2019.4 HF 5 through 2020.2.1, released between March 2020 and June 2020. FireEye discovered the attack and suggests it is a state- sponsored global intrusion campaign by a group named UNC2452 – though many industry experts are attributing the attack to APT29, a group of hackers associated with the Russian Foreign Intelligence Service.
[Show full text]