State-Sponsored Actors Compromise Thousands Through SolarWinds Supply Chain Attack
A sophisticated supply chain attack involving trojanized SolarWinds Orion updates affects numerous government and private organizations globally. Cisco Talos actively monitors the situation and urges immediate patching following DHS guidance.
Cisco Talos closely monitors a massive supply chain attack where a likely state-sponsored actor compromises thousands of high-value government and private organizations worldwide. The adversaries achieve this breach by trojanizing updates to the SolarWinds Orion IT monitoring and management software, specifically targeting a component within versions 2019.4 HF 5 through 2020.2.1.
The compromised, digitally signed updates remain available on the SolarWinds website until very recently, allowing the threat actors to quietly distribute a backdoor tracked by security researchers. Investigations show that the malicious infrastructure operates as far back as late February, demonstrating a highly sophisticated and patient campaign that initially surfaces through FireEye's own breach disclosure.
Due to conflicting guidance between SolarWinds and the DHS regarding affected versions, Talos strongly urges all customers to follow DHS recommendations. Users must immediately install the upcoming SolarWinds Orion Platform version 2020.2.1 HF 2, which replaces the compromised component and provides essential security enhancements to mitigate this severe threat.