Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

riversedge

(70,447 posts)
Sat Apr 17, 2021, 09:57 AM Apr 2021

Russian hackers exploited gaps in U.S. defenses and spent months in government and corporate network




A 'Worst Nightmare' Cyberattack: The Untold Story Of The SolarWinds Hack
Russian hackers exploited gaps in U.S. defenses and spent months in government and corporate networks in one of the most effective cyber


?s=20




A 'Worst Nightmare' Cyberattack: The Untold Story Of The SolarWinds Hack


https://www.npr.org/2021/04/16/985439655/a-worst-nightmare-cyberattack-the-untold-story-of-the-solarwinds-hack

April 16, 202110:05 AM ET



An NPR investigation into the SolarWinds attack reveals a hack unlike any other, launched by a sophisticated adversary intent on exploiting the soft underbelly of our digital lives.

Zoë van Dijk for NPR


....................................

"This release includes bug fixes, increased stability and performance improvements."
..................................


Last spring, a Texas-based company called SolarWinds made one such software update available to its customers. It was supposed to provide the regular fare — bug fixes, performance enhancements — to the company's popular network management system, a software program called Orion that keeps a watchful eye on all the various components in a company's network. Customers simply had to log into the company's software development website, type a password and then wait for the update to land seamlessly onto their servers.

The routine update, it turns out, is no longer so routine.


Hackers believed to be directed by the Russian intelligence service, the SVR, used that routine software update to slip malicious code into Orion's software and then used it as a vehicle for a massive cyberattack against America.
Article continues after sponsor message

"Eighteen thousand [customers] was our best estimate of who may have downloaded the code between March and June of 2020,"


.....................................
..........................................

NPR's months-long examination of that landmark attack — based on interviews with dozens of players from company officials to victims to cyber forensics experts who investigated, and intelligence officials who are in the process of calibrating the Biden administration's response — reveals a hack unlike any other, launched by a sophisticated adversary who took aim at a soft underbelly of digital life: the routine software update. ................................
1 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Russian hackers exploited gaps in U.S. defenses and spent months in government and corporate network (Original Post) riversedge Apr 2021 OP
This message was self-deleted by its author Chin music Apr 2021 #1

Response to riversedge (Original post)

Latest Discussions»Issue Forums»Editorials & Other Articles»Russian hackers exploited...