/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Analysis finds 24+ organizations that installed SolarWinds code, including Cisco, Intel, Nvidia, VMware, Belkin, a CA hospital, and Kent State university

A Wall Street Journal analysis identified at least 24 organizations that installed software laced with malicious code by Russian hackers

Wall Street Journal

Context & Ripple Effects

The naming of specific victims turns an abstract incident into a concrete one. Reuters had already reported that under 18,000 SolarWinds customers were compromised between March and June via a poisoned Orion update, with DHS, Treasury, and Commerce among those hit; this Wall Street Journal analysis puts names on the list — Cisco, Intel, Nvidia, VMware, Belkin, a California hospital, and Kent State University — showing the blast radius spans chipmakers, networking vendors, healthcare, and higher education.

The story also sets up two threads the later coverage pulls: investigators went on to find the suspected Russian operation extended well beyond SolarWinds itself, with roughly 30% of victims having no connection to the software, and were probing whether the initial breach came through SolarWinds' engineering offices in Czechia, Poland, and Belarus rather than its US operations.

First-order effects

  • Each named organization — Cisco, Intel, Nvidia, VMware, Belkin, the California hospital, Kent State — must now determine what the laced code did inside its network, remediate, and decide how much to disclose to customers, regulators, and users whose data may have been exposed.
  • SolarWinds faces an immediate trust collapse among its installed base: the under-18,000 affected customers must treat every Orion update as untrusted until proven clean, freezing or slowing routine patching.

Second-order effects

  • Security vendors being victims cuts both ways — organizations that bought Cisco, Intel, or Nvidia products for their own defense now face the uncomfortable question of whether their suppliers' networks were used as a vantage point, forcing every vendor to publish assurance statements about its own environment.
  • Scrutiny shifts to SolarWinds' distributed engineering footprint: if the breach entered through its Czech, Polish, or Belarusian offices, other US software companies with offshore development centers face pressure to re-audit access controls and code-signing chains across all locations.

Third-order effects

  • If the pattern holds — and Microsoft's later report that Russia-backed Nobelium breached 14 more IT providers since May 2021 suggests it does — the software supply chain itself becomes the primary target, pushing toward regulated build-pipeline attestation and signed-update requirements across the industry.
  • The finding that many victims never touched SolarWinds points to a structural shift in espionage tradecraft: initial-access brokers and multiple intrusion paths mean perimeter-based victim lists understate campaigns, reshaping how regulators and insurers define breach scope.

The trend: Nation-state attackers are shifting from exploiting deployed software to poisoning the update pipelines that distribute it, making the software-delivery chain — not the endpoint — the contested ground.

Discussion

  • @dnvolz Dustin Volz on x
    From Cisco, Intel and VMWare to the likes of Kent State University and California hospitals: @WSJ identified infected computers at two dozen organizations that installed the tainted SolarWinds software, showing the wide reach of the suspected Russian hack https://www.wsj.com/...
  • @ericgeller Eric Geller on x
    Missed this yesterday, but Microsoft said it discovered “an additional malware that also affects the SolarWinds Orion product but has been determined to be likely unrelated to this compromise and used by a different threat actor.” https://www.microsoft.com/... Fun!
  • @ryanaraine Ryan Naraine on x
    SolarWinds supply chain hack twist: 1. New malware. 2. Unrelated to the known compromise. 3. Used by a different threat actor. 4. New malware is small persistence backdoor that allows remote code execution through SolarWinds web application server https://www.microsoft.com/...
  • @algotrdr Bill Harts on x
    Mostly for nerds (if you don't know what a DLL is don't bother reading): Fascinating Microsoft analysis of the SolarWinds hack. Surprise ending: MS found ANOTHER, unrelated hack that even affects the SW hack! (Appendix, “Additional malware discovered") https://www.microsoft.com/.…
  • @blackorbird @blackorbird on x
    #SolarWinds Important Update: 1.About DNS requests https://securelist.com/... decode tool: https://github.com/... 2.Complete attack process https://www.microsoft.com/... https://twitter.com/... https://twitter.com/...
  • @realdonaldtrump Donald J. Trump on x
    The Cyber Hack is far greater in the Fake News Media than in actuality. I have been fully briefed and everything is well under control. Russia, Russia, Russia is the priority chant when anything happens because Lamestream is, for mostly financial reasons, petrified of....
  • @realdonaldtrump Donald J. Trump on x
    ....discussing the possibility that it may be China (it may!). There could also have been a hit on our ridiculous voting machines during the election, which is now obvious that I won big, making it an even more corrupted embarrassment for the USA. @DNI_Ratcliffe @SecPompeo
  • @thomaswright08 Tom Wright on x
    Trump literally told Xi in person to keep building the concentration camps. https://twitter.com/...
  • @govctw Governor Christine Todd Whitman on x
    #Putin must have something over #Trump; the President has repeatedly come to Russia's defense, & now we see just how dangerous it is. These cyberattacks go to the heart of our government, putting our country in grave danger are likely worse than we know. https://www.washingtonpos…
  • @richardgrenell Richard Grenell on x
    “familiar with the speculation” is code for the gossip of the DC crowd. “No special insight” means no access to the actual facts. https://twitter.com/...
  • @ellenychang Ellen Chang on x
    If you don't follow cybersecurity attacks like me and @john_kreuzer, you should know this is extremely detrimental to security of the U.S. This attack was carefully orchestrated. https://twitter.com/...
  • @john_sipher John Sipher on x
    This is a terrible breach. Any public retaliation will not be in direct response but we be necessary push back for years of Russian malign activity against the US and its allies. We've mishandled Putin for over a decade. He's now clearly shown his stripes. https://www.nytimes.com…
  • @httech Hindustan on x
    The number of actual hacking victims has been one of many unanswered questions surrounding the cyber-attack... https://tech.hindustantimes.com/ ...
  • @caseyjohnellis Cje on x
    i was too busy unpacking this to notice his use of “The Cyber Hack” /me jots notes in the tshirt ideas book https://twitter.com/...
  • @kyledcheney Kyle Cheney on x
    Nearly all of government is on a war footing, demanding severe consequences for all-but-certain Russian hack — except Trump who provides cover for Russia and connects it to false claim of election hacking. https://twitter.com/...
  • @carlquintanilla Carl Quintanilla on x
    (Bloomberg) — At least 200 organizations, including government agencies and companies around the world, have been hacked as part of a suspected Russian cyber-attack that implanted malicious code in a widely used software program .. https://www.bloomberg.com/...
  • @debramessing Debra Messing on x
    Putin is attacking our country from the outside, and Trump is doing it from the inside. Hand in hand. What could be more urgent? https://twitter.com/...
  • @normative Julian Sanchez on x
    There is absolutely no way anyone can be sure any of this is “well under control.” They're either lying to him or he's lying. https://twitter.com/...
  • @politicalshort Nick Short on x
    “There was a significant effort to use a piece of third-party software to embed code inside of U.S. Govt systems & it appears systems of private companies & governments across the world as well...we can say pretty clearly that it was the Russians.” -Pompeo https://www.state.gov/.…
  • @nicoleperlroth Nicole Perlroth on x
    Trump has been pressuring associates to downplay the Russian hack on television, calling it a “hoax” behind closed doors. Latest not so greatest with @SangerNYT https://www.nytimes.com/...
  • @nytpolitics @nytpolitics on x
    Hours after Mike Pompeo told a conservative radio host that “we can say pretty clearly that it was the Russians” behind the vast hack of the federal government and U.S. industry, President Trump contradicted him and sought to muddy intelligence findings https://www.nytimes.com/..…
  • @brianstelter Brian Stelter on x
    “Privately, the president has called the hack a ‘hoax’ and pressured associates to downplay its significance and push alternate theories for who is responsible, two people familiar with the exchanges said.” https://www.nytimes.com/...
  • @jimsciutto Jim Sciutto on x
    This is gross national security malpractice. https://twitter.com/...
  • @luispatino92 Lucho Patio on x
    Do you want to read about the code part of the SolarWind security attack? This is the best post I found about the code that avoided being detected for months and reached some government systems in the USA. #100DaysOfCode https://www.microsoft.com/...
  • @c_c_krebs Chris Krebs on x
    Do not conflate voting system security and SolarWinds. The proof is in the paper. You can audit or recount again to confirm the outcome. Like they did in Georgia. And Michigan. And Wisconsin. And Arizona. Can't hack paper.
  • @jimsciutto Jim Sciutto on x
    New: WH officials were preparing to release a statement Friday assigning blame on Russia for recent massive cyberattack but were told to stand down, according to people familiar with plans. @Kevinliptakcnn reporting
  • @senwarren Elizabeth Warren on x
    I'm gravely concerned about this massive cyberattack. It demands a far more serious response than the President's tweets playing it down and defending Russia. https://www.washingtonpost.com/ ...
  • @levie Aaron Levie on x
    We're witnessing the criticality of having well staffed, well coordinated, and highly experienced cyber security and technical talent in the government.
  • @ophirgottlieb Ophir Gottlieb on x
    Hacked Networks will need to be “burned down to the ground” https://apnews.com/... - It's going to take months to kick elite hackers widely believed to be Russian out of the U.S. government networks they have been quietly rifling through since as far back as March.
  • @brento Brent Ozar on x
    “In an interesting turn of events, the investigation of the whole SolarWinds compromise led to the discovery of an additional malware that also affects the SolarWinds Orion product” Wow, keeps getting worse. See the “additional malware” section. https://www.microsoft.com/...
  • @file411 @file411 on x
    Good LORD: “whole SolarWinds compromise led to the discovery of an additional malware that also affects the SolarWinds Orion product but has been determined to be likely unrelated to this compromise and used by a different threat actor...” https://www.microsoft.com/... https://tw…
  • @gossithedog Kevin Beaumont on x
    In depth technical look at SolarWinds nation state activity from MS peeps, including more hunting details etc. Really proud of the teams here, everything been thrown at protecting everyone. https://www.microsoft.com/...
  • @jonathanvswan Jonathan Swan on x
    Sources briefed on the intelligence say the cyberattack was unequivocally Russia. Bottom line: Pompeo described reality and the president is attacking him for it. https://twitter.com/...
  • @stengel Richard Stengel on x
    “I think it's the case that now we can say pretty clearly that it was the Russians that engaged in this activity. This was a very significant effort.” Secretary of State Mike Pompeo https://www.nytimes.com/...
  • @andrewsolender Andrew Solender on x
    Trump breaks his silence on the cyber attack by: - Downplaying its severity - Contradicting his own officials by suggesting it may have been China instead of Russia - Connecting it to his voter fraud conspiracy theories https://twitter.com/...
  • @peterbakernyt Peter Baker on x
    Trump once again seeks to absolve Russia amid allegations of hostile action, contradicting Pompeo and other US officials by saying Beijing not Moscow may have been behind cyberattack and insisting it was not as a big a deal as reported. ⁦@SangerNYT⁩ https://www.nytimes.com/...
  • @brianbeutler Brian Beutler on x
    How will we ever crack the impenetrable Trump-Russia mystery?? https://twitter.com/...
  • @tackettdc Michael Tackett on x
    “Sec of State Mike Pompeo says Russia was “pretty clearly” behind the gravest cyberattack against the United States on record, the first administration official to publicly tie the Kremlin to the widespread intrusion...when President Trump has kept silent” https://apnews.com/...
  • @geoffrbennett Geoff Bennett on x
    AP: “Officials at the White House had been prepared to put out a statement Friday afternoon that accused Russia of being ‘the main actor’ in the hack, but were told at the last minute to stand down.” https://apnews.com/...
  • @briankrebs @briankrebs on x
    45 says all the experts (including his) are wrong: SolarWinds hack is hot air, no big deal. China — not Russia — may be responsible. In same breath, says hack could have affected the election. https://twitter.com/...
  • @jonathanvswan Jonathan Swan on x
    “A gap is widening between the POTUS and his SecState on this urgent matter of national security. @SecPompeo faces a choice in the coming days — whether to continue to tell the truth about the hack & whether begin to admit reality about the election.” https://www.axios.com/...
  • @homelanddems @homelanddems on x
    It is completely depraved for President Trump to just now crawl out of his shell to downplay the cyberattack on Fed networks and continue his disinformation campaign. He was silent as Federal agencies spent the last week scrambling to assess the damage. https://www.axios.com/...
  • @repadamschiff Adam Schiff on x
    Another day, another scandalous betrayal of our national security by this president. Another dishonest tweet that sounds like it could have been written in the Kremlin. Another obsequious display towards Putin. And yet another reason that Trump can't leave office fast enough. htt…
  • @tedlieu Ted Lieu on x
    Dear @realDonaldTrump: Can you please stop lying? We still don't know the full scale of the damage, and neither do you. But we do know your own @SecPompeo said Russia was behind this massive Cyber Hack. Why do you always bend the knee in front of Putin? What is wrong with you? ht…
  • @wesball Wes Ball on x
    It's so depressing a chunk of people wanted four more years of this lunacy. https://twitter.com/...
  • @jonathanvswan Jonathan Swan on x
    As his national security officials gather facts on this cyberattack, President Trump is spending ever-greater amounts of time discussing conspiracy theories with allies including Sidney Powell. https://twitter.com/...
  • @alivelshi Ali Velshi on x
    It guess “it also could be somebody sitting on their bed that weighs 400 pounds” https://twitter.com/...
  • @asemota Osaretin Victor Asemota on x
    I like the new Twitter notice. https://twitter.com/...
  • @rubengallego Ruben Gallego on x
    Voting machines aren't connected to the internet. Your own Secretary of State says it was Russia. It is so weird that you can't bring yourself to say anything bad about Putin or Russia. https://twitter.com/...
  • @margbrennan Margaret Brennan on x
    The Acting Chairman of Senate Intelligence @marcorubio also attributes the massive hacking of the US government & private industry to Russian intelligence. https://twitter.com/...
  • @gregpmiller Greg Miller on x
    Keeping his record of protecting/defending Putin in all circumstances intact. https://twitter.com/...
  • @oliverdarcy Oliver Darcy on x
    Who could have possibly guessed that in his first comment on the massive cyberattack that Trump would attack the media and play down blame on Russia? https://twitter.com/...
  • @pwnallthethings @pwnallthethings on x
    It is not a big deal and also it is the media's fault, oh wait, no actually it's China's fault, and therefore also a big deal, and also something something something therefore I won the election.
  • @jimsciutto Jim Sciutto on x
    Now the president is not just silent on Russia and the hack. He is deliberately running defense for the Kremlin by contradicting his own Secretary of State on Russian responsibility. https://twitter.com/...
  • @atrupar Aaron Rupar on x
    Did Putin write this? https://twitter.com/...
  • @kaitlancollins Kaitlan Collins on x
    Trump here floats that China may have been responsible for the massive hack of the federal government. Secretary of State Pompeo, tagged here, said yesterday, “We can say pretty clearly that it was the Russians that engaged in this activity.” https://twitter.com/...
  • @laurenwern Lauren Werner on x
    Putin's orange sock puppet is at it again. https://twitter.com/...
  • @aghamilton29 @aghamilton29 on x
    Trump never changes or learns. If people remember, he also dismissed Russia being behind the DNC hack, instead suggestion it could have been a 400 pound guy sitting in his bed. The guy is a clown and the circus is closing in a month. https://twitter.com/...
  • @b_fung Brian Fung on x
    Trump addresses the hack personally for the first time, says he's been briefed on the incident. https://twitter.com/...
  • @nicoleperlroth Nicole Perlroth on x
    The president has been telling associates that the Russia hack is a “hoax.” Been trying to confirm this a.m and then he just...tweeted it out... https://twitter.com/...