SolarWinds Supply Chain Attack Creates Unprecedented Cybersecurity Fallout
The SolarWinds supply chain compromise catches the security industry off guard and threatens critical infrastructure with potential physical consequences. A detailed timeline reveals how the massive intrusion unfolds through compromised software updates.
The SolarWinds supply chain attack stands as an unprecedented cybersecurity event due to its capability to cause significant physical consequences. Experts note that the breach impacts critical infrastructure providers, which potentially disrupts energy and manufacturing capacities. Despite frequent warnings from the security industry about supply chain risks, this massive compromise catches many people completely off guard.
The discovery of the attack begins on December 8, 2020, when cybersecurity firm FireEye announces it is the victim of a nation-state attack and its Red Team toolkit is stolen. Just days later, FireEye researchers detect that attackers enter a backdoor in the SolarWinds Orion software by trojanizing business software updates to distribute malware. FireEye dubs this malicious backdoor "SUNBURST."
Following the discovery, SolarWinds immediately notifies its customers via social media to upgrade their Orion Platform software. The company files an official SEC Form 8-K report acknowledging the cyberattack and releases two hotfix security patches to address the vulnerability. As investigators continue to piece together the events, the full extent of the damages remains unclear and may take years to tally.