All vulnerabilities
CRITICALSupply chainexploited in the wild

SC-SOLARWINDS-SUNBURST-2020

Software vendor · SolarWinds Orion

Summary

Disclosed in mid-December 2020, Russia-linked APT29 compromised the build environment of SolarWinds' Orion IT monitoring platform. Using a tool named SUNSPOT, the attackers injected the SUNBURST backdoor into Orion software builds between roughly March and June 2020, which were then distributed through normal signed software updates. Up to 17,000 customers received the trojanized update, though only a few hundred high-value government, technology and consulting targets received follow-on payloads. Initial access predated discovery by 14+ months.

References

Related vulnerabilities

All Supply chain →