logo

ICYMI: SolarWinds Compromise Update

ID: 8afa37df-425a-5593-8047-189876944945

STIX ID: report--8afa37df-425a-5593-8047-189876944945

Feed Name: ReliaQuest Blog

Threat Score
90/100

Date Published: 2021-01-08

Date Updated: 2026-04-29

...
...

This blog summarizes the SolarWinds supply-chain compromise through December 2020–January 2021: investigators discovered the SUNBURST backdoor (and a separate SUPERNOVA instance), described sophisticated APT behavior (likely UNC2452/APT29) using DGA-based C2 and victim-specific subdomains, and agencies (CISA, Microsoft, FireEye, FBI/NSA/ODNI) issued alerts, technical details, and mitigation advice; the post emphasizes hunting for IoCs, third-party risk assessment, and provides detection queries and resources for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.