Sources: state-backed Russian hacking group APT29, or Cozy Bear, is behind the hacks of US Treasury, NTIA, and FireEye
Treasury, Commerce, FireEye—were breached through an IT Management System called Solar Winds https://www.washingtonpost.com/ ... Dustin Volz / @dnvolz : Sen. Angus King says hack is especially bad as it emerges during haphazard presidential transition. Putin “can hire about 8,000 hackers for the price of one jet fighter,” King said. “We just learned the damage those hackers can do, if it is indeed Russia.” https://www.wsj.com/... Chris Bing / @bing_chris : Common refrain from sources: today's news about USG hacks (Commerce + Treasury) and the larger supply chain compromise at Solar Winds, an IT provider for the USG, is “just the tip of the iceberg” This breach is much worse than it appears atm. And it appears very bad already Chris Krebs / @c_c_krebs : If you're a SolarWinds customer & use the below product, assume compromise and immediately activate your incident response team. Odds are you're not affected, as this may be a resource intensive hack. Focus on your Crown Jewels. You can manage this. https://twitter.com/... https://twitter.com/...
UPDATE: Sources tell me that the victims—Treasury, Commerce, FireEye—were breached through an IT Management System called Solar Winds https://www.washingtonpost.com/ ...
Common refrain from sources: today's news about USG hacks (Commerce + Treasury) and the larger supply chain compromise at Solar Winds, an IT provider for the USG, is “just the tip of the iceberg” This breach is much worse than it appears atm. And it appears very bad already
Sen. Angus King says hack is especially bad as it emerges during haphazard presidential transition. Putin “can hire about 8,000 hackers for the price of one jet fighter,” King said. “We just learned the damage those hackers can do, if it is indeed Russia.” https://www.wsj.com/...
If you're a SolarWinds customer & use the below product, assume compromise and immediately activate your incident response team. Odds are you're not affected, as this may be a resource intensive hack. Focus on your Crown Jewels. You can manage this. https://twitter.com/... https:…
Relieved that next month we can finally have the head of our government do what cybersecurity professionals have been calling for for years. Attribution and Consequences. https://twitter.com/...
SOLARWINDS in statement said it is aware of a potential vulnerability related to updates of its Orion technology management software that were released between March and June of this year.