Firm that discovered CCleaner Compromise: there may be Others
ID: bf8983af-45d5-57b8-89f9-5dc46538b760
STIX ID: report--bf8983af-45d5-57b8-89f9-5dc46538b760
Feed Name: Security Ledger
Morphisec discovered that CCleaner’s build process was compromised: attackers injected malicious code into a Visual Studio runtime bundled with CCleaner, the compromised software was signed by Piriform and distributed widely (up to ~2 million copies, with ~700,000 machines affected in the first stage), and a small set of technology firms suffered a more sophisticated second-stage attack aimed at stealing intellectual property; Morphisec is re-evaluating past false positives to find similar supply-chain compromises while warning that such attacks are on the rise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
