Get Permission
Mounting evidence points to the "serious compromise" of SolarWinds' Orion software having been an intelligence gathering operation that was "likely" run by Russia, according to a joint U.S. intelligence assessment. It's the first public attribution to be issued by the Trump administration for the massive supply chain attack against SolarWinds.
The attack campaign compromised systems at thousands of organizations for up to nine months. It was discovered not by the National Security Agency, but rather by FireEye, a private cybersecurity firm based in California that was one of the supply chain attack victims.
Since FireEye on Dec. 13 issued an alert about the attack campaign, government investigators have been scrambling to ascertain what happened and how best to mitigate the damage.