On December 13th, a disclosure was made for a compromise in the SolarWinds IT Management software suite code base that made a supply chain attack possible for all SolarWinds customers. While it is unknown how many of the SolarWinds customers are facing impacts from the supply chain attack, it is widely acknowledged that this foothold is present on many systems. This ReliaQuest Threat Advisory Report contains more detail on the compromise, references to FireEye and Microsoft research, the ReliaQuest response including IOCs identified and detection signatures, and our advice to customers that have SolarWinds software within their network.
Threat Research Report: Solar Winds Supply Chain Attack (Solorigate/SUNBURST)
