logo

The SolarWinds Attack

ID: b3343cfd-fc4f-56a7-80ae-6dbc4047e65e

STIX ID: report--b3343cfd-fc4f-56a7-80ae-6dbc4047e65e

Feed Name: Wiz Blog

Threat Score
95/100

Date Published: 2021-02-01

Date Updated: 2026-05-01

...
...

# Executive Summary This report analyzes the SolarWinds supply-chain compromise that deployed backdoors (SUNBURST, SUNSPOT, SUPERNOVA) enabling a sophisticated, likely nation-state campaign to pivot from on-premises into cloud environments (notably Office 365/Azure AD) using identity-focused techniques such as Golden SAML; it provides a timeline, known IOCs, detection and response guidance for cloud security teams, and recommends scanning, identity monitoring, and mitigation steps for affected environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.