Microsoft: a Second, Different Threat Actor Had Also Infected SolarWinds With Malware

Reuters reports:
A second hacking group, different from the suspected Russian team now associated with the major SolarWinds data breach, also targeted the company’s products earlier this year, according to a security research blog by Microsoft. “The investigation of the whole SolarWinds compromise led to the discovery of an additional malware that also affects the SolarWinds Orion product but has been determined…

UK Use of Software Linked To Russia-Hack Runs Deep

The little-known Texas software company that’s been attacked by suspected Russian hackers has a sprawling reach among U.K. government agencies, potentially putting clients from the National Health Service to police forces at risk. From a report: SolarWinds, which fell victim to hackers who put a “backdoor” in the software giving them access to users’ computer networks, has been deployed by the…

SolarWinds Hides List of High-Profile Customers After Devastating Hack

SolarWinds has removed a list of high-profile clients from its website in the wake of a massive breach, “suggesting the company may be trying to obscure its clients in an effort to protect them from bad publicity,” reports The Verge. From the report: The list of vulnerable companies is much smaller than SolarWinds’ overall client list, so simply appearing on the…

Hackers at Center of Sprawling Spy Campaign Turned SolarWinds’ Dominance Against It

An anonymous reader shares a report: On an earnings call two months ago, SolarWinds Chief Executive Kevin Thompson touted how far the company had gone during his 11 years at the helm. There was not a database or an IT deployment model out there to which his Austin, Texas-based company did not provide some level of monitoring or management, he told…

SolarWinds Says 18,000 Customers Were Impacted by Recent Hack

IT software provider SolarWinds downplayed a recent security breach in documents filed with the US Securities and Exchange Commission on Monday. From a report: SolarWinds disclosed on Sunday that a nation-state hacker group breached its network and inserted malware in updates for Orion, a software application for IT inventory management and monitoring. Orion app versions 2019.4 through 2020.2.1, released between March…

Russia Breached Update Server Used by 300,000 Organizations, Including the NSA

Sunday Reuters reported that “a sophisticated hacking group” backed by “a foreign government” has stolen information from America’s Treasury Department, and also from “a U.S. agency responsible for deciding policy around the internet and telecommunications.” The Washington Post has since attributed the breach to “Russian government hackers,” and discovered it’s “part of a global espionage campaign that stretches back months, according…