The SolarWinds Attack
ID: b3343cfd-fc4f-56a7-80ae-6dbc4047e65e
STIX ID: report--b3343cfd-fc4f-56a7-80ae-6dbc4047e65e
Feed Name: Wiz Blog
# Executive Summary This report analyzes the SolarWinds supply-chain compromise that deployed backdoors (SUNBURST, SUNSPOT, SUPERNOVA) enabling a sophisticated, likely nation-state campaign to pivot from on-premises into cloud environments (notably Office 365/Azure AD) using identity-focused techniques such as Golden SAML; it provides a timeline, known IOCs, detection and response guidance for cloud security teams, and recommends scanning, identity monitoring, and mitigation steps for affected environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
