December 13, 2020

SolarWinds supply-chain hack disclosed

FireEye disclosed on December 13, 2020 that nation-state actors had compromised SolarWinds Orion software — inserting backdoorA hidden way to access a system bypassing normal security — often installed by attackers or left by developers. code into updates trusted by thousands of organizations.

What it was for

Screensaver SolarwindsThe SUNBURST trojan rode signed Orion builds into U.S. government agencies, MicrosoftThe software giant behind Windows, Office, Azure, and Xbox — founded by Bill Gates and Paul Allen., and Fortune 500 networks — the definitive supply-chain breach. DevOpsPractices combining software development and IT operations — automation, CI/CD, and faster releases. teams accelerated SBOM adoption, build-pipeline signing, and least-privilege for CI/CDCompact disc — an optical storage format for digital audio and data. — treating dependency and vendor updates as attack surfaces, not chores.

Why it's here

SolarWinds was the supply-chain compromise that made every vendor update suspect.

Why it mattered

It forced SBOMs, signed builds, and zero-trust into mainstream DevSecOps.

What it solved

Nothing initially — attackers piggybacked on trusted auto-update channels.

Media

  • Screensaver Solarwinds
    ImageScreensaver Solarwinds

    Screensaver author, screenshot by me, CC BY-SA 3.0, via wikimedia

Related