SolarWinds Orion Backdoor Triggers Widespread Supply Chain Security Response
A sophisticated supply chain attack compromises SolarWinds Orion updates, prompting immediate detection updates and scanning tools from Rapid7 to help organizations identify exposure.
A sophisticated supply chain attack targets the SolarWinds Orion IT monitoring platform, putting countless organizations at risk of compromise. FireEye identifies this campaign as UNC2452 and dubs the trojanized component SUNBURST, while Microsoft refers to the malware as Solorigate and updates its Defender antivirus accordingly to help catch the threat.
Rapid7 responds to the disclosure by deploying new detections in InsightIDR for activity related to vulnerable SolarWinds Orion versions. The company strongly advises all customers running versions 2019.4 through 2020.2.1 to upgrade immediately to version 2020.2.1 HF 1 to mitigate the risk of infection.
To help organizations hunt for the threat, Rapid7 provides specific tools for its various security products. InsightVM and Nexpose users receive remote checks and query builder instructions to locate affected assets, while Managed Detection and Response (MDR) customers benefit from active analysis of their existing log data for known indicators of compromise.