UPDATED 22:27 EDT / DECEMBER 14 2020

SECURITY

US government software provider SolarWinds confirms it was hacked

The hack of the U.S. Treasury and Commerce Departments, first reported Sunday to involve Russian state-sponsored hackers, today was officially attributed to the compromise of software from SolarWinds Worldwide LLC.

As previously reported by SiliconANGLE, SolarWinds software is used by large parts of the U.S. government including the U.S. military, the Pentagon, the State Department, the Justice Department, the National Aeronautics and Space Administration, the Executive Office of the President and the National Security Agency.

SolarWinds provided more details on the hack, saying that up to 18,000 of its customers downloaded a “compromised software update” that allowed hackers to spy unnoticed on businesses and agencies for nine months. Previously, SolarWinds said that its monitoring products released in March and June may have been tampered with — as long as nine months ago.

Although large parts of the U.S. government getting hacked is bad, SolarWinds has complied with the California Consumer Privacy Act, releasing a formal advisory stating that its “systems experienced a highly sophisticated, manual supply chain attack.”

Mark Carrigan, chief operating officer at PAS Global LLC, told SiliconANGLE that given the massive global scale of installations, the stakes are high with the SolarWinds hack. “Many of these installations are across highly sensitive industrial operations where network visibility is traditionally weaker,” he said. “In fact, just today the ESCC, whose members include some of the largest U.S. power utility companies, gathered to discuss the emerging threat and how to respond.”

He added that organizations across every industry must react by first identifying where SolarWinds software is installed across their environments. “From there, they must further hone in on their inventory by determining the versions that are running to evaluate the vulnerability risk that may or may not be present,” he said. “Without doing so, these risks get scaled in tandem with the vulnerabilities, and from the industrial perspective, this jeopardizes critical functions that impact everyday life.”

Brandon Hoffman, chief information security officer at cybersecurity firm Netenrich Inc., noted that a link to the FireEye hack early this month might be a coincidence but nothing more.

“It’s natural to think that just after the FireEye breach, adversaries turned their tools to use and perpetrated this breach of the Commerce Department,” Hoffman said. “However, careful examination of this seems to lead us to the conclusion that this has been going on much longer. The type of attack described to date involves several low and slow techniques. The very term advanced persistent threat was coined to describe an attack just like this.”

The key takeaway, while the damage is being examined, is to determine if the organization is at risk, Hoffman added. “For any customer of SolarWinds Orion, it is worth digging as deep as possible to understand the implications,” he said.

Image: SolarWinds

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.