Interagency Task Force - United States Department of State https://t.co/px4m3F8TLX
https://t.co/VxT0iGCcQz
It ends now https://t.co/oWBZgCXP49
You are heard

https://t.co/FTcaAxTIwF
+ so many more
https://t.co/noZryBzzwx
We know

More from Dannielle (Dossy) Blumenthal PhD

SolarWinds follow up. Very good tweet explaining what happened.


Basically what this means is that SolarWinds itself was exploited. Someone posted an infected update as legitimate (digitally signed), leading customers to download a bad update.

“Multiple trojanized updates were digitally signed from March - May 2020 and posted to the SolarWinds updates website” https://t.co/8e3bMFWXYu


FireEye then explains that infected organizations were approached and exploited. This is a separate Step 2.

At this point, information is already going to “malicious domains” without extra intervention, after the malware does nothing for “up to two weeks”

More from Crime

You May Also Like