The U.S. Treasury Department was part of a massive supply chain attack on the SolarWinds IT management platform by Russiaâs APT 29 group. Todayâs columnist, Sam Curry of Cybereason, offers some analysis of the prolific hack and advice for security teams on how to respond. R BoedCreative CommonsAttribution 4.0 International
News over the weekend of a massive breach by Russiaâs APT 29 against the U.S. Treasury and U.S. Commerce Departments was eye-opening in its intensity. In addition, the CISA emergency directive urging all public and private sector organizations to assess their exposure and disconnect or power down the SolarWinds Orion products the attacks were tied to was a rare move: CISA issued such a directive for only the fifth time in its history.