Source |
CybeReason |
Identifiant |
2146483 |
Date de publication |
2021-01-05 19:42:44 (vue: 2021-01-05 20:05:46) |
Titre |
Contextualizing Microsoft\'s Source Code Exposure in the SolarWinds Attacks |
Texte |
In the middle of December, IT management software provider SolarWinds revealed in a security advisory that it had fallen victim to a sophisticated supply chain attack. The offensive involved the placement of a backdoor known as SUNBURST into versions 2019.4 HF 5, 2020.2 with no hotfix installed and 2020.2 HF 1 of the company's Orion Platform software. If executed, SUNBURST allowed an attacker to compromise the server running the Orion build. |
Notes |
|
Envoyé |
Oui |
Condensat |
2 with 2019 2020 advisory allowed attack attacker attacks backdoor build chain code company compromise contextualizing december executed exposure fallen had hotfix installed and involved known management microsoft middle offensive orion placement platform provider revealed running security server software solarwinds sophisticated source sunburst supply versions victim |
Tags |
|
Stories |
Solardwinds
Solardwinds
|
Move |
|