Categories: SecurityWorkspace

SolarWinds Issues Fix After Massive Hacking Campaign

Network tools maker SolarWinds has issued security fixes for its flagship Orion platform after the tool was discovered to have been used in a major hacking campaign earlier this month.

The company said it issued two patches on 14 and 15 December, a day after it disclosed on 13 December that Orion had been hacked.

The company also released fixes for all other versions of the Orion platform, including a fix for customers using unsupported versions.

“Sunburst” refers to what SolarWinds called a “very sophisticated supply chain attack” that inserted a vulnerability into Orion.

‘Supernova’

It later emerged the platform had also been hacked by a second, unrelated malware strain, called “Supernova”, which was deployed via a previously undetected software vulnerability in Orion.

The security fixes protect customers against both Sunburst and Supernova, SolarWinds said.

Following the company’s initial disclosure of the hac, it emerged that the Orion had been used to breach numerous US government departments and private companies.

The “Sunburst” attack is currently known to have affected the US Treasury Department, the National Telecommunications and Information Administration and the Department of Homeland Security, as well as Microsoft, Cisco, Intel,  Nvidia and UK accountants Deloitte.

A UK security source has said a small number of British organisations are likely to have been affected.

Nation-state hack

Some industry watchers have indicated it could take more than a year for organisations to determine whether they have been affected by the attack, which began in March.

US lawmakers have indicated they suspect Russian hackers to have carried out the “Sunburst” attack with the backing of the country’s government, although no attribution has yet formally been made.

“It’s clearly a sophisticated intelligence operation and no doubt was done by a state actor. And we’ll get around to attribution of that at a time and place of our choosing,” US national security adviser Robert O’Brien told Fox News.

Russia has denied any connection to the attack.

Liviu Arsene, a researcher at Bitdefender, said attacks on the supply chain are likely to become more common next year.

“Either for political or economic reasons, supply chain attacks will likely affect even industry verticals that have rarely been hit in the past, such as real-estate or healthcare,” he said.

He added that research, pharmaceuticals and healthcare organisations are likely to face increased threats.

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Bill Gates Hits Out At Elon Musk Over Children Deaths

Elon Musk responds, after Microsoft co-founder Bill Gates lashes out at Musk and Doge in…

3 days ago

Celsius Founder Alex Mashinsky Sentenced To 12 Years In Prison

Founder of former cryptocurrency lender Celsius Network, Alex Mashinsky, receives stiff prison sentence for fraud

3 days ago

Apple Developing Specialised Chips For Smart Glasses, AI Servers – Report

Specialised silicon is reportedly being developed inhouse by Apple for its smart glasses, Macbooks, and…

3 days ago

Tesla Fails In Attempt To Trademark ‘Robotaxi’ – Report

US Patent and Trademark Office denies Tesla attempt to trademark the term 'Robotaxi', but another…

4 days ago

Google Partners Elementl Power To Develop Nuclear Projects

Amid growing energy demand from AI systems, Google to provide capital for three nuclear projects…

4 days ago

White House To Redraft Biden’s AI Chip Export Rule

Relief for Nvidia and others? Trump administration says US intends to scrap Biden rule to…

4 days ago