Bose Work Remote Promo
Bose Work Remote Mobile Promo
Take Our Survey on Your IoT/Collaboration Plans & You Could Win a 60" 4K UHD Display!
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

My TechDecisions

  • COVID-19 Update
  • Best of Tech Decisions
  • Topics
    • Video
    • Audio
    • Mobility
    • Unified Communications
    • IT Infrastructure
    • Network Security
    • Physical Security
    • Facility
    • Compliance
  • RFP Resources
  • Downloads
  • Podcasts
  • Subscribe
  • Project of the Week
  • About Us
    SEARCH
Network Security, News

SolarWinds CEO: Company Might Not Be the Only Compromise

SolarWinds CEO Sudhakar Ramakrishna lays out attack timeline and says this should be a wake up call for the tech industry to share attack information.

January 14, 2021 Zachary Comeau Leave a Comment

SolarWinds CEO

In a new blog, SolarWinds’ CEO laid out what it is doing to respond to the compromise of its Orion IT management platform and what it knows so far about the attack.

As many cybersecurity and IT experts have been saying, SolarWinds’ CEO Sudhakar Ramakrishna called the attack – which the company codenames Sunburst – one of the most intrusive and sophisticated in history.

“As we and industry experts have noted previously, the Sunburst attack appears to be one of the most complex and sophisticated cyberattacks in history,” Ramakrishna wrote in a blog post.

While other experts and U.S. government officials have suggested the hackers are affiliated with the Russian government, Ramakrishna said the company’s investigators have not independently verified the identity of the attackers.

The malicious code itself was designed to allow the cyber actors to enter a customer’s IT environment. Working with cybersecurity firms KPMG and CrowdStrike, SolarWinds located the malicious code injection source and reverse-engineered the code to allow researchers to learn more about the attack method.

According to the blog, the threat actor was in SolarWinds’ environment in September 2019, and a new release of the Orion platform in October contained modifications designed to test the attacker’s ability to insert code into the company’s builds.

Last February, an updated version of the malicious code injection source that inserted the Sunburst code into the Orion Platform was released.

However, the attackers were undetected, and removed the malicious code from SolarWinds’ environment last June.

Read Next: SolarWinds Hackers Viewed Microsoft Source Code; Victim List Grows to 250

Despite investigating and patching vulnerabilities, the company didn’t identify anything that would suggest the Orion platform was compromised.

It wasn’t until Dec. 12 that the company was notified of the compromise and began collaboration with law enforcement and others in the tech and cybersecurity industry.

Ramakrishna says the company has identified two different customer support incidents that it believes might be attributable to the attack. Each time, the company didn’t detect the malicious code.

The possibility of this kind of large-scale cyber attack has kept IT and cybersecurity professionals up at night, and now that it’s happening, there are fears that SolarWinds may not be the only initial access vector.

In the blog, Ramakrishna said he hopes this event ushers in a new level of collaboration and information sharing within the technology industry to prevent these attacks.

“Our concern is that right now similar processes may exist in software development environments at other companies throughout the world,” he wrote.

“The severity and complexity of this attack has taught us that more effectively combatting similar attacks in the future will require an industry-wide approach as well as public-private partnerships that leverage the skills, insight, knowledge, and resources of all constituents.”

Tagged With: Cybersecurity, SolarWinds

Related Content:

  • hybrid work endpoints Study: Security, Scalability Top Concerns of Remote Work
  • Crestron 70 Series Scheduling Panels Microsoft Teams Microsoft Teams Panels Now Generally Available
  • delivery robots Delivery Robots are Coming To Campuses
  • IBM Siemens Red hat Hybrid Cloud IBM, Siemens, Red Hat Collaborate On Hybrid Cloud…

Free downloadable guide you may like:

  • Introducing the IT Pro MBA: Vetting Technology

    At some point in your career there is going to come a time when you are tasked with reviewing and vetting new tech to implement into your company. Sometimes the hardest part of the whole thing is just getting started. In this new series from My TechDecisions, the IT Pro MBA: Vetting Technology guide deep-dives […]

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Get the FREE Tech Decisions eNewsletter

Sign up Today!

Latest Downloads

Introducing the IT Pro MBA: Vetting Technology

At some point in your career there is going to come a time when you are tasked with reviewing and vetting new tech to implement into your company. ...

9 Technology Products to Help Combat COVID-19 Spread in the Workplace

As the Coronavirus continues on and leads us further into uncertainty, the question remains, “when do we return to the office?” For some the answer...

Top 9 Reasons Enterprise IT Leaders Are Moving Their Video Surveillance to the Eagle Eye Cloud

Working in IT has enough challenges without adding in the complications of surveillance video. Things like total cost of maintenance, how the VMA m...

View All Downloads

Would you like your latest project featured on TechDecisions as Project of the Week?

Apply Today!
Sharp Microsoft Collaboration HQ Logo

Learn More About the
Windows Collaboration Display

More from Our Sister Publications

Get the latest news about AV integrators and Security installers from our sister publications:

Commercial IntegratorSecurity Sales

Footer

TechDecisions

  • Home
  • Welcome to TechDecisions
  • Subscribe to the Newsletter
  • Contact Us
  • Media Solutions & Advertising
  • Comment Guidelines
  • RSS Feeds
  • Terms of Use
  • Privacy Policy
  • Twitter
  • Facebook
  • Linkedin

Free Technology Guides

FREE Downloadable resources from TechDecisions provide timely insight into the issues that IT, A/V, and Security end-users, managers, and decision makers are facing in commercial, corporate, education, institutional, and other vertical markets

View all Guides
TD Project of the Week

Get your latest project featured on TechDecisions Project of the Week. Submit your work once and it will be eligible for all upcoming weeks.

Enter Today!

© 2021 Emerald X, LLC. All rights reserved.