US officials say the hacking campaign involving SolarWinds would likely still be undetected if not for a security alert at FireEye that triggered scrutiny
Wall Street Journal
Related Coverage
- SolarWinds hack is espionage, not terrorism Telegraph
- Security News This Week: Russia's SolarWinds Hack Is a Historic Mess Wired
- Security experts are ‘freaking out’ about how foreign hackers carried out the ‘most pristine espionage effort’ in modern history right under the US's nose Business Insider
- Hackers' Monthslong Head Start Hamstrings Probe of U.S. Breach Bloomberg
- Sunburst: connecting the dots in the DNS requests Securelist
- SolarWinds hack: What we know, and don't know, so far GeekWire
- SolarWinds Hackers Broke Into the Federal Agency That Oversees the Nation's Nukes Gizmodo
Discussion
-
@michaeldweiss
Michael Weiss
on x
Years is a long time to be exfiltrating data from computer systems. https://www.wsj.com/... https://twitter.com/...
-
@nycsouthpaw
Southpaw
on x
Have been thinking about these two lines in @dnvolz's story. Taken together, they seem to indicate that the public case for attributing the Solarwinds attack to Russia is: It was very well done. https://www.wsj.com/... https://twitter.com/...
-
@dancrenshawtx
Dan Crenshaw
on x
There must be government action, likely sanctions. But we can't stop there. These Russian oligarchs own property assets here in the US. Pass HR4189, which amends FSIA to allow victims of cyber attacks to sue Russia directly. We need better cyber defense, and better offense. https…
-
@waronprivacy
WartOnPrivacy
on x
“A warning that someone had used the employee's credentials to log into the company's VPN from an unrecognized device - the kind of security message that corporate workers routinely delete” Deleted because they're who logged in https://www.wsj.com/... #cybersecurity #infosec
-
@adryenn
Adryenn Ashley
on x
20 years ago was my job was to break into online banking (hired by the banks). That's when I discovered that there is no such thing as security and privacy. The hack of SolarWinds shows just how deep and insidious foreign interference into our leadership and data really is. https…
-
@crimealytics
Jeff Asher
on x
Important point raised about the strength of the public SVR attribution in this great piece from @dnvolz and @bobmcmillan. The SVR doesn't make much sense IMHO. https://www.wsj.com/... https://twitter.com/...
-
@dnvolz
Dustin Volz
on x
The suspected Russian hackers were victims of their own success and hubris. After breaching scores of targets undetected for many months, they went after a harder one: a huge cyber firm with vast investigative resources. That led to the hack's unraveling. https://www.wsj.com/...
-
@dnvolz
Dustin Volz
on x
FireEye CEO Kevin Mandia said the hack of his firm through SolarWinds was like “a sniper round through a bulletproof vest.” Once SolarWinds was suspected, FireEye analysts scoured 50,000 lines of code in search of a “needle in a stack of needles.” https://www.wsj.com/...