Source: Treasury's hackers used a flaw in a SolarWinds product; SolarWinds, which touts 300K+ customers, says the flaw was the result of a “supply chain attack”
and it has the Kremlin's fingerprints all over it. https://www.bloomberg.com/... Thomas Brewster / @iblametom : New - A review of contract records shows DOD, FBI, DHS, Veterans Affairs and many other U.S. agencies have purchased SolarWinds Orion, the tool used as a launchpad for the huge government and private industry espionage campaign disclosed this weekend. https://www.forbes.com/... Raphael Satter / @razhael : New from @jc_stubbs & team: The scope of the SolarWinds breach is potentially enormous, but cyber investigators across the industry say signs suggest the hackers honed in on relatively few targets: “They are using this like a scalpel,” one told me. https://www.reuters.com/... Matthew Green / @matthew_d_green : If the US government handed you $50m/yr and Presidential authority to address supply chain attacks on US systems, what would you do? Pam Keith / @pamkeithfl : THIS is what happens when you allow a likely Russian asset to be president. My worry is about Russia getting Intel & clandestine asset info. I am also more than a little irritated that once again Trump has said NOT ONE WORD about Russia attacking us. The man is a menace. https://twitter.com/... Brian Barrett / @brbarrett : It's going to be a while before we know the full extent of how bad this Russia hack really is https://www.wired.com/... Brian Beutler / @brianbeutler : Am I correct that Trump has said zero words about this? https://twitter.com/... Daniel Lippman / @dlippman : The hack's extended duration raises a huge red flag about the attacks' impact on the government, Sue Gordon, a former top deputy in ODNI, told me. “It is massively disruptive once you have long-term penetration by a nation-state,” she said. https://www.politico.com/... @mzbat : 2021 will be the year of large scale infra attacks. This week, we're getting a preview. “The attackers in question have been especially discrete in using network infrastructure... and using a variety of cloud hosting services for network infrastructure.” https://www.wired.com/... Dustin Volz / @dnvolz : RUMOR CONTROL: “Dominion Voting Systems does not now nor has it ever used the SolarWinds Orion Platform, which was subject of the DHS emergency directive dated December 13, 2020,” a Dominion spokeswoman says. via @AlexaCorse cc: @CISAgov @CISAKrebs Barbara Malmet / @b52malmet : This is totally getting lost in the vaccine/electoral college news. And it is HUGE. https://twitter.com/... Dustin Volz / @dnvolz : Pompeo appeared to confirm Russian involvement in the SolarWinds hack in radio intvw. “I can't say much other than it's been a consistent effort of the Russians to try and get into American servers, not only those of government agencies but of businesses” https://www.wsj.com/... Naveed Jamali / @naveedajamali : Russia didn't just gain access to email, they compromised networks through an update to a network monitoring tool. Agencies include the FBI, all branches of the military, and many others. This is one of the largest most recent cyber espionage operations. https://www.bloomberg.com/... Nicole Perlroth / @nicoleperlroth : “Power Down.” If you are just joining, USG federal agencies and untold number of SolarWind clients have been compromised via a malicious SolarWinds software update for as long as six months and CISA, the decapitated cyber agency, is telling SolarWinds clients to power it down. https://twitter.com/... Jake Williams / @malwarejake : Okay folks, let's talk about SolarWinds. For those not familiar with it, SolarWinds is a network management system (NMS). It's probably the most ubiquitous NMS out there, so we shouldn't jump to conclusions that FireEye and Treasury were both breached by an SolarWinds vuln. 1/ @briankrebs : Researchers at @oscontext say the first traffic they saw to the malware controllers in the SolarWinds infrastructure was on 4/4/2020. Fireeye said the malware was config'd to sleep for 2 weeks post-install. Suggests first targets were hit sometime in March https://www.fireeye.com/... @cisagov : Last night we issued an emergency directive to mitigate the compromise involving SolarWinds Orion products: https://cisa.gov/.... We urge all our partners—in the public & private sectors—to assess their exposure to this compromise and to secure their networks. Dustin Volz / @dnvolz : One person familiar with the SolarWinds hack said the Russian campaign was a “10” on a scale of one to 10, in terms of its likely severity and national security implications. https://www.wsj.com/... Alex Stamos / @alexstamos : There have been attempts by Google, BITS and others to better coordinate vendor risk management but none have really taken off. We need a deeper focus on security program maturity and transparency up and down the stack. Alex Stamos / @alexstamos : 3. The investment our government puts into offense and intelligence gathering versus defense is spectacularly off. @C_C_Krebs built a great org with CISA, but they have something like 2,000 employees for the entire critical infrastructure and cyber mission. NSA has over 40k. Alex Stamos / @alexstamos : If we had a liability carrot-and-stick approach, where these reviews were conducted by professional staff, penalties were applied by a competent regulator, and we had 400 public pages to read on the root causes in six months, other companies could learn and improve. Alex Stamos / @alexstamos : I hope the timing of this reveal means that the Biden administration and Congress will really think about investing in defense and motivating companies to be responsible in 2021. I also hope we see some defensive operators in key administration cyber roles. Alex Stamos / @alexstamos : As a result, there are dozens of companies that represent critical, systemic risk across the public and private sector and most of the “security community” has interacted with none of them. The outside pressure that has pushed consumer IT to improve does not exist for most of IT. @briankrebs : Hacks at US Treasury, Commerce Dept. tied to supply chain attack on network monitoring tools from SolarWinds. CISA is telling agencies to unplug affected SolarWinds products. Given breadth of SW customer base, this is likely to be 1st of many disclosures https://krebsonsecurity.com/ ... Eric Geller / @ericgeller : 🚨 CISA has issued an emergency order requiring federal agencies to disable SolarWinds IT products, which hackers exploited to penetrate Treasury, NTIA, and possibly other agencies. https://cyber.dhs.gov/... Disconnection “is the only known mitigation measure currently available.” Catalin Cimpanu / @campuscodi : tl;dr: The SolarWinds hack is more like the Avast CCleanear breach, not the M.E.Doc/NotPetya incident. Only certain high-value targets were hit. If you run a pet store chain and use SolarWinds, you and your dog food inventory are most likely fine. https://twitter.com/... Kenn White / @kennwhite : Considerable engineering went in to evading detection, including steganography: “HTTP response bodies attempt to appear like benign XML related to .NET assemblies, but command data...is spread across multiple strings that are disguised as GUID and HEX strings” https://twitter.com/... Andy Greenberg / @a_greenberg : Some here pointing to the SolarWinds hack as the other Sandworm/NotPetya shoe dropping. Still early, but this looks like targeted spying as you'd expect from APT29/SVR, not Sandworm/GRU-style disruption. Not yet sure it's less serious, just very different. https://www.reuters.com/... Andy Greenberg / @a_greenberg : Just imagine, however, if this operation had been Sandworm rather than APT29, and had been focused on disruption instead of espionage: It had the keys to the kingdom across hundreds of US networks through most of this incredibly fraught pandemic/remote work/election year. Dave Kennedy / @hackingdave : Also for those giving @FireEye hell last week and poking fun and jest at their data breach because they were a security company, do you think your threat model would have protected against this? Some folks owe some apologies. Dmitri Alperovitch / @dalperovitch : BUT here is the good news - no adversary has enough human resources to effectively exploit every potential victim. They pretty much HAVE to focus on those they care most about. But no doubt this is squarely in the #goodproblemtohave department for them. Very impressive op 2/2 Eric Geller / @ericgeller : Microsoft has published a report on the hacking campaign that has breached several federal agencies. It confirms that the intruders used SolarWinds product vulnerabilities for initial access and then forged authentication tokens to spread further. https://msrc-blog.microsoft.com/ ...
For NSA Director Gen. Nakasone, the attack ranks among the biggest crises of his time in office...He'll have to answer why private industry, rather than the multibillion-dollar enterprise he runs from a war room in Fort Meade, was first to raise the alarm. https://www.nytimes.com…
The full compromised package is still being hosted online as well 😓 hxxps://downloads.solarwinds[.]com/ solarwinds/CatalogResources/Core/2019.4 / 2019.4.5220.20574/SolarWinds-Core- v2019.4.5220-Hotfix5.msp https://twitter.com/...
This is a massive, dangerous hack that hit governments and corporations alike, worldwide — and it has the Kremlin's fingerprints all over it. https://www.bloomberg.com/...
New - A review of contract records shows DOD, FBI, DHS, Veterans Affairs and many other U.S. agencies have purchased SolarWinds Orion, the tool used as a launchpad for the huge government and private industry espionage campaign disclosed this weekend. https://www.forbes.com/...
New from @jc_stubbs & team: The scope of the SolarWinds breach is potentially enormous, but cyber investigators across the industry say signs suggest the hackers honed in on relatively few targets: “They are using this like a scalpel,” one told me. https://www.reuters.com/...
RUMOR CONTROL: “Dominion Voting Systems does not now nor has it ever used the SolarWinds Orion Platform, which was subject of the DHS emergency directive dated December 13, 2020,” a Dominion spokeswoman says. via @AlexaCorse cc: @CISAgov @CISAKrebs
THIS is what happens when you allow a likely Russian asset to be president. My worry is about Russia getting Intel & clandestine asset info. I am also more than a little irritated that once again Trump has said NOT ONE WORD about Russia attacking us. The man is a menace. https://…
Pompeo appeared to confirm Russian involvement in the SolarWinds hack in radio intvw. “I can't say much other than it's been a consistent effort of the Russians to try and get into American servers, not only those of government agencies but of businesses” https://www.wsj.com/...
The hack's extended duration raises a huge red flag about the attacks' impact on the government, Sue Gordon, a former top deputy in ODNI, told me. “It is massively disruptive once you have long-term penetration by a nation-state,” she said. https://www.politico.com/...
2021 will be the year of large scale infra attacks. This week, we're getting a preview. “The attackers in question have been especially discrete in using network infrastructure... and using a variety of cloud hosting services for network infrastructure.” https://www.wired.com/...
Russia didn't just gain access to email, they compromised networks through an update to a network monitoring tool. Agencies include the FBI, all branches of the military, and many others. This is one of the largest most recent cyber espionage operations. https://www.bloomberg.com…
Okay folks, let's talk about SolarWinds. For those not familiar with it, SolarWinds is a network management system (NMS). It's probably the most ubiquitous NMS out there, so we shouldn't jump to conclusions that FireEye and Treasury were both breached by an SolarWinds vuln. 1/
“Power Down.” If you are just joining, USG federal agencies and untold number of SolarWind clients have been compromised via a malicious SolarWinds software update for as long as six months and CISA, the decapitated cyber agency, is telling SolarWinds clients to power it down. ht…
Researchers at @oscontext say the first traffic they saw to the malware controllers in the SolarWinds infrastructure was on 4/4/2020. Fireeye said the malware was config'd to sleep for 2 weeks post-install. Suggests first targets were hit sometime in March https://www.fireeye.com…
Last night we issued an emergency directive to mitigate the compromise involving SolarWinds Orion products: https://cisa.gov/.... We urge all our partners—in the public & private sectors—to assess their exposure to this compromise and to secure their networks.
One person familiar with the SolarWinds hack said the Russian campaign was a “10” on a scale of one to 10, in terms of its likely severity and national security implications. https://www.wsj.com/...
There have been attempts by Google, BITS and others to better coordinate vendor risk management but none have really taken off. We need a deeper focus on security program maturity and transparency up and down the stack.
3. The investment our government puts into offense and intelligence gathering versus defense is spectacularly off. @C_C_Krebs built a great org with CISA, but they have something like 2,000 employees for the entire critical infrastructure and cyber mission. NSA has over 40k.
If we had a liability carrot-and-stick approach, where these reviews were conducted by professional staff, penalties were applied by a competent regulator, and we had 400 public pages to read on the root causes in six months, other companies could learn and improve.
I hope the timing of this reveal means that the Biden administration and Congress will really think about investing in defense and motivating companies to be responsible in 2021. I also hope we see some defensive operators in key administration cyber roles.
As a result, there are dozens of companies that represent critical, systemic risk across the public and private sector and most of the “security community” has interacted with none of them. The outside pressure that has pushed consumer IT to improve does not exist for most of IT.
Hacks at US Treasury, Commerce Dept. tied to supply chain attack on network monitoring tools from SolarWinds. CISA is telling agencies to unplug affected SolarWinds products. Given breadth of SW customer base, this is likely to be 1st of many disclosures https://krebsonsecurity.c…
🚨 CISA has issued an emergency order requiring federal agencies to disable SolarWinds IT products, which hackers exploited to penetrate Treasury, NTIA, and possibly other agencies. https://cyber.dhs.gov/... Disconnection “is the only known mitigation measure currently available.”
Considerable engineering went in to evading detection, including steganography: “HTTP response bodies attempt to appear like benign XML related to .NET assemblies, but command data...is spread across multiple strings that are disguised as GUID and HEX strings” https://twitter.com…
tl;dr: The SolarWinds hack is more like the Avast CCleanear breach, not the M.E.Doc/NotPetya incident. Only certain high-value targets were hit. If you run a pet store chain and use SolarWinds, you and your dog food inventory are most likely fine. https://twitter.com/...
BUT here is the good news - no adversary has enough human resources to effectively exploit every potential victim. They pretty much HAVE to focus on those they care most about. But no doubt this is squarely in the #goodproblemtohave department for them. Very impressive op 2/2
Also for those giving @FireEye hell last week and poking fun and jest at their data breach because they were a security company, do you think your threat model would have protected against this? Some folks owe some apologies.
Some here pointing to the SolarWinds hack as the other Sandworm/NotPetya shoe dropping. Still early, but this looks like targeted spying as you'd expect from APT29/SVR, not Sandworm/GRU-style disruption. Not yet sure it's less serious, just very different. https://www.reuters.com…
Just imagine, however, if this operation had been Sandworm rather than APT29, and had been focused on disruption instead of espionage: It had the keys to the kingdom across hundreds of US networks through most of this incredibly fraught pandemic/remote work/election year.
Microsoft has published a report on the hacking campaign that has breached several federal agencies. It confirms that the intruders used SolarWinds product vulnerabilities for initial access and then forged authentication tokens to spread further. https://msrc-blog.microsoft.com/…
There it is - @CISAgov issues Emergency Directive 21-10, directing Fed civilian agencies to take action on SolarWinds compromise. Still digesting, but this is a strong move. Proud of the team. Everyone else should refer to this as they chart next steps. https://cyber.dhs.gov/...
Since earlier in year there has been a serious supply chain attack impacting a very popular enterprise management tool, and multivendor SAML (authentication) attacks allowing for maintained access and data exfiltration. IOCs, Azure Sentinel queries etc: https://msrc-blog.microsof…
Just released by FireEye, confirming signed updates from SolarWinds enterprise monitoring software were backdoored. This is the real deal folks. https://www.fireeye.com/... https://twitter.com/...