SolarWinds

How the SEC charges against SolarWinds highlight the cybersecurity liability of software companies
On October 30, 2023, the Securities and Exchange Commission (SEC) filed a civil complaint against SolarWinds Corporation and its chief information security officer, Timothy G. Brown, for violating federal securities laws by ...

SolarWinds CISO Sued for Fraud by US SEC
Richi Jennings | | CISO, CISO duties, CISO Incompetency, CISO reporting structure, SB Blogwatch, SEC, Securities and Exchange Commission, SolarWinds, SolarWinds Orion Supply Chain, SolarWinds Vulnerability, solarwinds123, SolarWindsOrion, Sudhakar Ramakrishna, SUNBURST, Sunburst malware, Sunburst Vuln, Timothy Brown, U.S. Securities and Exchange Commission
The password was ‘solarwinds123’: SUNBURST still reverberates as SolarWinds CISO Timothy Brown co-defends SEC lawsuit ...
Security Boulevard

CISA Put Securing Open Source Software on the Roadmap
The government’s top cybersecurity agency is laying out steps it says are necessary to ensure that open source software, which is increasingly ubiquitous in modern IT environments, is secure. The eight-page document ...
Security Boulevard

SEC Sends Wells Notice to SolarWinds Executives
Christopher Burgess | | Orion, SEC, Security Exchange Commission, SolarWinds, SUNBURST, Wells Notice
On June 23, 2023, SolarWinds revealed via an SEC Form 8-K filing that the U.S. Securities and Exchange Commission (SEC) notified the company that “certain current and former executive officers and employees ...
Security Boulevard
Beyond SolarWinds: 6 More Notable Software Supply Chain Attacks
rezilion | | Application Security, Kaseya, SBOM, Software Attack Surface Management, software bill of materials, software supply chain attacks, SolarWinds, Uncategorized, Vulnerability Management
SolarWinds has become almost a household name and for all the wrong reasons: beginning in 2019, the system management company was the target of one of the largest software supply chain attacks ...

Protecting the Digital Experience
Optimizing digital experience is all the rage today, as the tech industry finally got religion about ensuring end customers—whether external buyers or internal employees—can seamlessly and simply do what they need to ...
Security Boulevard

Software Supply Chain Attacks: Clear and Present Danger
Eran Orzel | | CI/CD pipeline, DEVOPS, DevSecOps, security, software supply chain security, SolarWinds, Supply Chain Attacks, supply chain security
More than a year after the SolarWinds Sunburst attack and most companies are still exposed to software supply chain attacks. In a study conducted by Argon Security at Aqua Security, it was ...
Security Boulevard

New Russian Hacks Revealed—but U.S. Says it’s Microsoft’s Fault
Richi Jennings | | APT29, Cozy Bear, Microsoft, Russia, SB Blogwatch, SolarWinds, This story is a massive nothingburger
Microsoft has issued another of its “look how clever we are” writeups of detecting APT29 hackers. But the U.S. government sees it differently ...
Security Boulevard

How the SolarWinds Hack (almost) went Undetected
Erik Hjelmvik | | ascii-art, backdoor, C2, dns, SEC-T, SolarWinds, Solorigate, Stage 2, STAGE2, SUNBURST, video, YouTube
My lightning talk from the SEC-T 0x0D conference has now been published on YouTube. This 13 minute talk covers tactics and techniques that the SolarWinds hackers used in order to avoid being ...

Supply Chain Security – Not As Easy As it Looks
The massive exploit of SolarWinds is a prime example of what is called a “supply chain” vulnerability. The vast majority of those impacted by the Russian SolarWinds attack probably had never even ...
Security Boulevard