ICYMI: SolarWinds Compromise Update
ID: 8afa37df-425a-5593-8047-189876944945
STIX ID: report--8afa37df-425a-5593-8047-189876944945
Feed Name: ReliaQuest Blog
This blog summarizes the SolarWinds supply-chain compromise through December 2020–January 2021: investigators discovered the SUNBURST backdoor (and a separate SUPERNOVA instance), described sophisticated APT behavior (likely UNC2452/APT29) using DGA-based C2 and victim-specific subdomains, and agencies (CISA, Microsoft, FireEye, FBI/NSA/ODNI) issued alerts, technical details, and mitigation advice; the post emphasizes hunting for IoCs, third-party risk assessment, and provides detection queries and resources for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
