SolarWinds Compromise: What security teams need to know
ID: 68200818-7554-5632-bd92-39904f41d6e0
STIX ID: report--68200818-7554-5632-bd92-39904f41d6e0
Feed Name: ReliaQuest Blog
Threat Score
The report details a highly sophisticated, narrowly targeted supply-chain compromise of SolarWinds Orion updates (SUNBURST/Solorigate) used to deploy a backdoor, mimic legitimate Orion traffic, steal credentials and SAML token-signing material, and exfiltrate sensitive data across multiple sectors and regions; detection queries and mitigation guidance are provided, and attribution is suggested to be a state-sponsored APT (e.g., APT29/UNC2452) but remains unconfirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
