SolarWinds hires ex-CISA Director Christopher Krebs as an independent consultant to help its crisis response after the hack
Group's software was exploited by suspected Russian hackers to spy on governments and businesses — The American technology company at the centre …
Financial Times
Context & Ripple Effects
SolarWinds’ compromise had already reached US government systems: investigators reported access to DHS internal communications alongside penetrations at Treasury and Commerce. The company is now bringing in former CISA director Christopher Krebs as an independent adviser while its response is under intense public-sector scrutiny.
The hiring sits between questions over whether the intrusion touched SolarWinds’ engineering operations and later disclosures that attackers had occupied its Office 365 email environment for at least nine months. It makes outside crisis oversight part of the company’s effort to address a breach with consequences beyond its own network.
First-order effects
SolarWinds gains an independent crisis-response adviser with federal cybersecurity experience as it manages a suspected Russian campaign affecting government and business customers.
Government customers and other affected users get a more visible external point of assurance during SolarWinds’ investigation and remediation effort.
Second-order effects
The appointment raises the bar for SolarWinds’ explanations of how the compromise occurred, including investigators’ examination of potential links to its engineering offices and the company’s earlier review of suspicious activity with Microsoft.
Microsoft and SolarWinds’ other security partners face greater pressure to show how warning signs and remediation steps are being coordinated for shared customers.
Third-order effects
The episode points toward critical software suppliers treating independent security leadership as a crisis-management requirement when a compromise spreads into government networks.
Later SEC Wells notices to SolarWinds executives over the 2020 incident show how breach response and disclosure can become individual accountability issues, not solely corporate ones.
The trend: Supply-chain cyber incidents are pushing software vendors toward more independent oversight and tighter accountability for detection, response, and disclosure.
Wow. Congratulations @C_C_Krebs! You keep up this career path and people are going to think you are only attracted to the hardest dumpster fires to put out. Good luck, not that you need it! https://twitter.com/...
When I hear “Alex Stamos was hired by aCompany A”, I must assume “Company A” to be inherently evil/bad. Past examples: Yahoo (mass breaches that were covered up), Facebook, Zoom (intentionally bypassing security features that caused a backdoor and the exec framing people) https:/…
From a counterintelligence POV this is a really interesting attack. Access to sealed court documents would potentially reveal a lot of useful intelligence information. https://twitter.com/...
It looks like two branches of the US government were infiltrated yesterday. Hackers apparently broke into sealed Federal court records. An enormous wealth of confidential personal and corporate information... https://twitter.com/...
Warner also said the number of big name SolarWinds victims that have not come forward yet would “surprise the hell” out of people. Warner's Senate Intel Committee received a classified briefing Wednesday on SolarWinds from intel agencies, so this probably isn't idle commentary. h…
Because this was absolutely lost in yesterday's news cycle re Russia & our ECF “...that greatly risk compromising highly sensitive non-public documents stored on CM/ECF,...particularly sealed filing...” cc @SeamusHughes @burgessct @lauferlaw @lachlan https://www.uscourts.gov/... …
NOTICE: Possible security vulnerabilities that risk compromising highly sensitive non-public documents stored on national case filing system are under investigation. New security measures will be posted ASAP. See MOED website: https://www.moed.uscourts.gov/ ... and https://uscour…
Federal courts are immediately adding new security procedures to protect highly sensitive confidential documents filed with the courts after the recent disclosure of widespread cybersecurity breaches. https://www.uscourts.gov/...
Fed court system reveals “apparent compromise” of electronic filing system that put at risk “highly sensitive non-public documents.” Sensitive docs must be filed on paper or by USB drive and will be stored on special system. https://www.uscourts.gov/... https://twitter.com/...
U.S. federal courts investigating an “apparent compromise of the confidentiality of the CM/ECF system.” The District of Minnesota sent out a notice tonight: “Do not file anything in CM/ECF under seal until you receive further instruction from this Court.” https://www.uscourts.gov…
Just days ago, I was discussing with someone whether these court filings had been compromised by SolarWinds (bc certain people appear to have non-public information about some court proceedings). https://twitter.com/...
New: The electronic filing system used by federal courts has likely been breached in the SolarWinds hack, extending to another branch of government the impact of a suspected Russian cyber-espionage campaign. https://www.wsj.com/...
I talked with the @dnvolz about the hack of the Judiciary branch “Documents like these are a road map of investigations...In the right hands, they could tip off a target of investigation, be it an individual or a country's intelligence apparatus.” https://www.wsj.com/...