3 ms·
Wasn't the root cause of this attack someone setting a prod system password to 'solarwinds123'? Not very sophisticated nor unforseeable. Not just any prod syst
by grun3 3y ago
Wasn't the root cause of this attack someone setting a prod system password to 'solarwinds123'? Not very sophisticated nor unforseeable.
Not just any prod system... the one that distributed their trusted updates to their entire customer base I believe.
- donmcronald 3y agoHaha. I didn't follow it. After a bit of searching I had to laugh. They got owned by the 'hunter2' meme and call it a highly sophisticated and unforeseeable attack.
- mlyle 3y agoWell, all the subsequent steps after the initial breach were fairly fancy. But still, not a great posture overall.
- miguelazo 3y agoExactly... the initial foothold was a joke. And the bottom line is that important management folks were warned about serious issues many times.
- mac-chaffee 3y agoNo, that was a separate incident: https://www.theregister.com/2020/12/16/solarwinds_github_password/ https://www.theregister.com/2020/12/16/solarwinds_github_pas... From what I can tell, all we know is that the attackers definitely got into their build system (since the trojan was signed), and we know they moved laterally through exploits in various Microsoft products: https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach https://en.wikipedia.org/wiki/2020_United_States_federal_gov...
- wharfjumper 3y agoWill we see the SEC issue proceedings against Microsoft?