The hack

| No Comments

Wrote about it yesterday: Hacking - a curious incident

It's real and it's massive - from the United States Cybersecurity and Infrastructure Security Agency

Active Exploitation of SolarWinds Software
The Cybersecurity and Infrastructure Security Agency (CISA) is aware of active exploitation of SolarWinds Orion Platform software versions 2019.4 HF 5 through 2020.2.1 HF 1, released between March 2020 and June 2020.

CISA encourages affected organizations to read the SolarWinds and FireEye advisories for more information and FireEye’s GitHub page for detection countermeasures:

SolarWinds makes software that helps large organizations manage their network and IT infrastructure. Monitoring network and server performance, databases, trouble tickets and service desk. The basic tasks.  They are used by a lot of corporations, our government, military and yes, Dominion Voting Systems.

The issue here is not just the initial breach.  The core issue is that it installs backdoors into the infected machines which lay dormant until triggered - either by an external signal or a length of time. These systems will need to be taken down to bare metal and rebuilt. More as I hear about it.

Leave a comment

March 2023

Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31  

About this Entry

This page contains a single entry by DaveH published on December 14, 2020 10:37 AM.

Would not be surprised was the previous entry in this blog.

And back home - Bellingham is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Monthly Archives

Pages

OpenID accepted here Learn more about OpenID
Powered by Movable Type 5.2.9