***THREAD***

I’ve been on the phone with colleagues about the hack all morning. None of us can figure out why #CISA chose this particular response to the breach. Couple of things struck us as curious.

The agencies targeted are not responding how you might expect...

More from Internet

SolarWinds follow up. Very good tweet explaining what happened.


Basically what this means is that SolarWinds itself was exploited. Someone posted an infected update as legitimate (digitally signed), leading customers to download a bad update.

“Multiple trojanized updates were digitally signed from March - May 2020 and posted to the SolarWinds updates website” https://t.co/8e3bMFWXYu


FireEye then explains that infected organizations were approached and exploited. This is a separate Step 2.

At this point, information is already going to “malicious domains” without extra intervention, after the malware does nothing for “up to two weeks”

You May Also Like