Showing posts sorted by relevance for query solarwinds. Sort by date Show all posts
Showing posts sorted by relevance for query solarwinds. Sort by date Show all posts

21 December 2020

Microsoft responds to sophisticated cyberattacks via SolarWinds Orion


Microsoft is aware of a sophisticated attack that utilizes malicious SolarWinds software. On December 17, 2020, Brad Smith posted a blog sharing the most up to date information and detailed technical information for defenders.


As this is an ongoing investigation, Microsoft cybersecurity teams continue to act as first responders to these attacks. We know that customers and partners will have ongoing questions and Microsoft is committed to providing timely updates as new information becomes available. We will make updates through our Microsoft Security Response Center (MSRC) blog at https://aka.ms/solorigate.

There are a number of published resources to assist customers in securing their environments:
We have published a blog outlining this dynamic threat landscape and the principles with which we are approaching the investigation.
We have published an anchor blog with technical details of the attack. This blog will be updated with new information as the investigation continues. Customers should look to this blog as the one stop for updates on the sophisticated attack.
Microsoft Defender antivirus and Microsoft Defender for Endpoint have released protections for the malicious SolarWinds software and other artifacts from the attack.
Microsoft Azure Sentinel has released guidance to help Azure Sentinel customers hunt in their environments for related activity we have observed with this sophisticated attack.
Microsoft 365 Defender and Microsoft Defender for Endpoint customers should review the Threat Analytics article within the Defender console (sign-in is required) for information about detection and potential impact to their environments.
For any Microsoft Threat Experts (MTE) customers, where we have observed suspicious activity in the customers’ environments, we have completed Targeted Account Notifications.
If a customer has any product support related needs, please continue to direct them to Microsoft Support (CSS) who remain the primary place for all customer support needs.
For Identity professionals and Microsoft 365 admin, we have published a blog with guidance on how to protect Microsoft 365 from on-premises attacks.


Microsoft Blog Posts
December 13 - Customer Guidance on Recent Nation-State Cyber Attacks – Microsoft Security Response Center
December 13 - Important steps for customers to protect themselves from recent nation-state cyberattacks
December 15 - Ensuring customers are protected from Solorigate
December 16 - SolarWinds Post-Compromise Hunting with Azure Sentinel - Microsoft Tech Community
December 17 - A moment of reckoning: the need for a strong and global cybersecurity response
December 18 - Analyzing Solorigate, the compromised DLL file that started a sophisticated cyberattack, and how Microsoft Defender helps protect - Microsoft Security
December 18 - Protecting Microsoft 365 from on-premises attacks


Advisories & Additional Resources
If your customer has a specific question regarding FireEye, please refer them to the FireEye Advisory.
If your customer has a specific question regarding SolarWinds, please refer them to the SolarWinds Advisory.
The Cybersecurity and Infrastructure Security Agency (CISA) has published a set of information and guidance here. For individual country-specific guidance, customers and partners should refer to information from the appropriate law enforcement or other government entity in that jurisdiction.


20 January 2021

Malwarebytes said it was hacked by the same group who breached SolarWinds


US cyber-security firm Malwarebytes today said it was hacked by the same group which breached IT software company SolarWinds last year.

Malwarebytes said its intrusion is not related to the SolarWinds supply chain incident since the company doesn't use any of SolarWinds software in its internal network.

Instead, the security firm said the hackers breached its internal systems by exploiting a dormant email protection product within its Office 365 tenant.

Malwarebytes said it learned of the intrusion from the Microsoft Security Response Center (MSRC) on December 15, which detected suspicious activity coming from the dormant Office 365 security app.

At the time, Microsoft was auditing its Office 365 and Azure infrastructures for signs of malicious apps created by the SolarWinds hackers, also known in cyber-security circles as UNC2452 or Dark Halo.

Malwarebytes said that once it learned of the breach, it began an internal investigation to determine what hackers accessed.

"After an extensive investigation, we determined the attacker only gained access to a limited subset of internal company emails," said today Marcin Kleczynski, Malwarebytes co-founder and current CEO.

www.zdnet.com


15 December 2020

Reds under the beds? Actually the Ruskies are a lot more widespread than that...

Concern is gathering over the effects of the backdoor inserted into SolarWinds' network monitoring software on Britain's public sector – as tight-lipped government departments refuse to say whether UK institutions were accessed by Russian spies.

As reported in the small hours of this morning by The Register, it appears the downloads page for SolarWinds' Orion Windows monitoring platform was altered by Kremlin hackers – known as APT29, aka Cozy Bear – so that victims fetched and installed a tampered-with version that included a remote-control backdoor.

This malicious code was detailed by FireEye, which itself said it was earlier hacked by state-level miscreants. Said victims of the Orion job are said to include the Treasury and the Dept of Commerce at the US government. It now also looks like the Department of Homeland Security has also been breached! It's not clear at this stage whether FireEye was also hacked via a dodgy Orion install.

Research by The Register has shown that SolarWinds' Orion is used widely across the British public sector, ranging from the Home Office and Ministry of Defence through NHS hospitals and trusts, right down to local city councils.

WASHINGTON (AP) — Top national security agencies confirmed Tuesday (5 Jan 2021) that Russia was likely responsible for a massive hack of U.S. government departments and corporations, rejecting President Donald Trump’s claim that China might be to blame.

www.theregister.com


14 December 2020

SolarWinds admits product updates were subverted by nation state while FireEye warns exploit is rampant

SolarWinds' "Orion" IT monitoring platform has been compromised, and speculation is swirling that it was used in attacks on major US government agencies that could also be linked to last week's revelation that FireEye's top hacking tools have been accessed.

A statement from Kevin Thompson, SolarWinds president and CEO, said the company is "aware of a potential vulnerability which if present is currently believed to be related to updates which were released between March and June 2020 to our Orion monitoring products."

"We believe that this vulnerability is the result of a highly sophisticated, targeted and manual supply chain attack by a nation state. We are acting in close coordination with FireEye, the Federal Bureau of Investigation, the intelligence community, and other law enforcement to investigate these matters. As such, we are limited as to what we can share at this time."

www.theregister.com