CISA's Einstein, which cost billions and monitors US agencies' networks for bad actors, missed the SolarWinds hack, which now counts the NIH among its victims
When Russian hackers first slipped their digital Trojan horses into federal government computer systems, probably sometime in the spring …
Washington Post
Related Coverage
- Malicious Domain in SolarWinds Hack Turned into ‘Killswitch’ Krebs on Security · Brian Krebs
- SolarWinds Hack Could Affect 18K Customers Krebs on Security · Brian Krebs
- SolarWinds' shares drop 22 per cent. But what's this? $286m in stock sales just before hack announced? The Register · Kieren McCarthy
- Billions Spent on U.S. Defenses Failed to Detect Giant Russian Hack New York Times
- Russia's Hacking Frenzy Is a Reckoning Wired · Lily Hay Newman
- How suspected Russian hackers outed their massive cyberattack Politico
- SolarWinds hides list of high-profile customers after devastating hack The Verge · Russell Brandom
- SolarWinds: Why the Sunburst hack is so serious BBC · Joe Tidy
- SolarWinds: company at the core of the Orion hack falls under scrutiny The Guardian · Kari Paul
- SolarWinds Cyber Attacks Raise Questions About The Company's Security Practices And Liability Forbes · Jody Westby
- Microsoft unleashes ‘Death Star’ on SolarWinds hackers in extraordinary response to breach GeekWire · Christopher Budd
- US intelligence agencies warn large-scale cyber attack is ‘ongoing’ Financial Times
Discussion
-
@matthew_d_green
Matthew Green
on x
Alex buries the lede in his editorial on the SolarWinds breach. https://twitter.com/... https://twitter.com/...
-
@douglasblackmon
Douglas A. Blackmon
on x
These are the things that happen under an incompetent president like @realDonaldTrump, focused only on himself, his cabinet members coerced into paralysis, no interest in whether the govt functions: massive spy attack, not enough vaccine, millions duped by his lies. https://twitt…
-
@zooko
@zooko
on x
Great Op-Ed by Alex Stamos on what the USA Federal Government should do about cyberattacks like the one that has just been revealed in which Putin's spy agency (probably) has secretly had access to the computers of most of the top USA federal agencies: https://www.washingtonpost.…
-
@malwarejake
Jake Williams
on x
Great reporting from @lilyhnewman on what this latest round of breaches could mean for the future of cybersecurity policy. https://www.wired.com/...
-
@radiochio
Steve Chiotakis
on x
Not a peep from the president about this. https://twitter.com/...
-
@campuscodi
Catalin Cimpanu
on x
Is anyone else tweeting about SolarWinds having problems with MAGA and conspiracy theory bots too? or is it just me? I've had tweets flooded with weird stuff like this and the Dominion voting machines angle all week https://twitter.com/...
-
@kasparov63
Garry Kasparov
on x
Remember when Trump and Putin talked about US-Russian cooperation on cyber-security? Leaving the doors open for the thief is a form of cooperation, I suppose. https://twitter.com/...
-
@adamgoldmannyt
Adam Goldman
on x
It now is clear that the broad Russian espionage attack on the United States government and private companies ranks among the greatest intelligence failures of modern times. https://www.nytimes.com/...
-
@marietjeschaake
Marietje Schaake
on x
Great policy suggestions by @alexstamos on how to protect people from harms caused by cyberattacks, the need to put analysis in the public domain and to ensure accountability > How to defend against the next Russian cyberattacks ↘️ https://www.washingtonpost.com/ ...
-
@wiredscience
@wiredscience
on x
Despite years of warning, the US still has no good answer for the sort of “supply chain” attack that let Russia run wild. https://www.wired.com/...
-
@find_evil
Jackie Singh
on x
OK, I'm starting my first infosec investing group. We're going to focus on using the information we know about the state of companies' cybersecurity programs to sniff out leaks, anticipate breaches, and trade on breach news. I'll be the fund manager 😉 Who's in? https://twitter.co…
-
@wired
@wired
on x
This week, several major US government agencies discovered that their digital systems were breached by a months-long Russian espionage operation. The breadth of the attacks will take months to fully understand, but it's clearly a moment of reckoning. https://www.wired.com/...
-
@joetidy
Joe Tidy
on x
The SolarWinds hack is the largest in years with huge implications for private and public organisations and national security. I've tried to boil it all down here. Clearly a lot more to come... https://www.bbc.co.uk/...
-
@mdudas
Mike Dudas
on x
Silver Lake sold $158M and Thoma Bravo sold $128M worth of SolarWinds stock less than a week before massive government hack was publicly disclosed. Will be wild if this is determined to be insider trading by some of the most elite PE firms in the world. https://www.washingtonpost…
-
@briankrebs
@briankrebs
on x
A key malicious domain used to control systems hacked via the SolarWinds compromise was commandeered and turned into a “killswitch” that in some cases forced the Sunburst malware to terminate itself & prevent further execution, FireEye told KrebsOnSecurity https://krebsonsecurity…
-
@senblumenthal
Richard Blumenthal
on x
Americans deserve to know the impact of this staggering cyberattack—& how Cozy Bear reportedly slipped into systems under our sleuths' noses. With no sign of a timeline for disclosure, I'll be demanding more facts. https://www.washingtonpost.com/ ...
-
@alexadobrien
Alexa O'Brien
on x
“But Einstein, operated by the DHS's CISA, was not equipped to find novel malware or Internet connections, despite a 2018 report from the GAO suggesting that building such capability might be a wise investment.” https://www.washingtonpost.com/ ...
-
@lisaeinstein
Lisa Einstein
on x
“...as something best understood by the lawyers who prosecute cybercrime & defend breached companies...the Biden cybersec. team should include the voices of people who have real experience preventing, detecting & responding to crises like the 1 our country is facing today."(4/4)
-
@lisaeinstein
Lisa Einstein
on x
📣Fantastic article by @alexstamos on long overdue changes the United States needs to make to defend against the next Russian cyberattacks. Favorite quotes below: ⬇️ (1/4) https://twitter.com/...
-
@tombossert
Thomas P. Bossert
on x
The US public is sick, our leaders distracted, and we are under cyberattack. This isn't about SolarWinds anymore. It hasn't been for months. The Russians are in our networks at a very fragile time. What are we going to do about it? My @nytimes OpEd https://www.nytimes.com/...
-
@kylieatwood
Kylie Atwood
on x
🚨 Trump “must use whatever leverage he can muster to protect the US & severely punish the Russians.” Biden must plan to “take charge of this crisis” & assume communications about this matter are being read by Russia & assume any gov data/email could be falsified, Bossert writes. …
-
@dnvolz
Dustin Volz
on x
“While all indicators point to the Russian government, the United States, and ideally its allies, must publicly and formally attribute responsibility for these hacks. If it is Russia, President Trump must make it clear to Vladimir Putin that these actions are unacceptable.”
-
@dandrezner
Daniel W. Drezner
on x
It's striking that the former Trump officials who have been the most outspoken in their criticism of the president are in the homeland security portfolio. https://twitter.com/...
-
@nicoleperlroth
Nicole Perlroth
on x
“President Trump is on the verge of leaving behind a federal government, and perhaps a large number of major industries, compromised by the Russian government.” https://twitter.com/...
-
@kaitlancollins
Kaitlan Collins
on x
Trump's former homeland security adviser: “The magnitude of this ongoing attack is hard to overstate...The Russians have had access to a number of important networks for 6 to 9 months...The access they now enjoy could be used for far more than spying.” https://www.nytimes.com/...
-
@dnvolz
Dustin Volz
on x
“President Trump must get past his grievances about the election and govern for the remainder of his term. This moment requires unity, purpose and discipline. An intrusion so brazen and of this size and scope cannot be tolerated by any sovereign nation.”
-
@ewong
Edward Wong
on x
“President Trump must get past his grievances about the election and govern for the remainder of his term. This moment requires unity, purpose and discipline. An intrusion so brazen and of this size and scope cannot be tolerated.” — Trump ex-homeland security adviser @TomBossert …
-
@alaneyre1
Alan Eyre
on x
I thought it was very bad. It seems I underestimated. https://www.nytimes.com/...
-
@normative
Julian Sanchez
on x
The “ongoing” is important to stress. We know how they got in now. That doesn't mean anyone's sure they're out, and we probably won't be for a while. https://twitter.com/...
-
@marcambinder
Marc Ambinder
on x
COOP: the IC and agencies deemed essential were kneecapped by the pandemic. To enforce distancing, lots of folks who worked on classified projects were put on rotation and worked from home. We did not have a fully functioning defense because our defenders hadn't prepared. https:/…
-
@dnvolz
Dustin Volz
on x
Trump's former homeland security advisor, in new op-ed, writes: “The magnitude of this ongoing attack is hard to overstate ... While the Russians did not have the time to gain complete control over every network they hacked, they most certainly did gain it over hundreds of them.”…
-
@jonhurwitz
Jon Hurwitz
on x
This is coming from Trump's own former Homeland Security Adviser. How can you be a patriotic American and not be disturbed by this? https://twitter.com/...
-
@brett_mcgurk
Brett McGurk
on x
Tom was the most competent and experienced member of Trump's national security team. So he was asked to leave. The NSC's cyber security unit was dismantled. Trump never warned Putin against further intrusions. Sadly, the pattern.👇 https://twitter.com/...