logo

SolarWinds Compromise: What security teams need to know

ID: 68200818-7554-5632-bd92-39904f41d6e0

STIX ID: report--68200818-7554-5632-bd92-39904f41d6e0

Feed Name: ReliaQuest Blog

Threat Score
95/100

Date Published: 2020-12-14

Date Updated: 2026-04-29

...
...

The report details a highly sophisticated, narrowly targeted supply-chain compromise of SolarWinds Orion updates (SUNBURST/Solorigate) used to deploy a backdoor, mimic legitimate Orion traffic, steal credentials and SAML token-signing material, and exfiltrate sensitive data across multiple sectors and regions; detection queries and mitigation guidance are provided, and attribution is suggested to be a state-sponsored APT (e.g., APT29/UNC2452) but remains unconfirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.