"Solarwinds123": Hacked IT Company Used Weak Password, While Backdoor Access Peddled On Underground Forums

"Solarwinds123": Hacked IT Company Used Weak Password, While Backdo...


Tyler Durden's Photo
BY TYLER DURDEN
WEDNESDAY, DEC 16, 2020 - 10:00

Hacked Texas-based IT infrastructure provider SolarWinds was warned over weak password security last year, after security researcher Vinoth Kumar discovered that the company used "solarwinds123" to protect their update server.

"This could have been done by any attacker, easily," said Kumar, according to Reuters.

On Monday, SolarWinds confirmed that their flagship network management software, Orion, was the target of an international cyberespionage operation which the Washington Post pinned on government-backed Russian hackers - who inserted malicious code into Orion software updates and pushed it out to almost 18,000 customers. 

The malicious updates - sent between March and June, when America was hunkering down to weather the first wave of coronavirus infections - was “perfect timing for a perfect storm,” said Kim Peretti, who co-chairs Atlanta-based law firm Alston & Bird’s cybersecurity preparedness and response team.

Assessing the damage would be difficult, she said.

We may not know the true impact for many months, if not more – if not ever,” she said. -Reuters

Included in the breach were the US Treasury, the Commerce Department's National Telecommunications and Information Administration (NTIA) and other government agencies.

Meanwhile, Reuters also reports that "multiple criminals have offered to sell access to SolarWinds’ computers through underground forums, according to two researchers who separately had access to those forums."

One of those offering claimed access over the Exploit forum in 2017 was known as “fxmsp” and is wanted by the FBI “for involvement in several high-profile incidents,” said Mark Arena, chief executive of cybercrime intelligence firm Intel471. Arena informed his company’s clients, which include U.S. law enforcement agencies. -Reuters

According to the report, neither the weak password or the stolen access are considered the most likely source of the current intrusion, however Kyle Hanslovan, the cofounder of Maryland-based cybersecurity company Huntress, noticed days after the SolarWinds hack that malicious updates were still available for download.

Dominion?

On Monday, screenshots began floating around of Dominion Voting Systems with a solarwinds logo below a login screen, implying that the 2020 US election may have been compromised by hackers, as opposed to on purpose as Trump and his allies have claimed.

Journalist Kim Zetter, however, pointed out that while Dominion does or did use a SolarWinds product, it wasn't their Orion software which was compromised. 

The company's stock has fallen over 25% since Friday's price of $23.50, currently sitting below $18. The company announced on December 9 that CEO Kevin Thompson would be replaced after 11 years at the helm with Sudhakar Ramakrishna, the former CEO of Pulse Secure.

Views: 23

Comment

You need to be a member of 12160 Social Network to add comments!

Join 12160 Social Network

"Destroying the New World Order"

TOP CONTENT THIS WEEK

THANK YOU FOR SUPPORTING THE SITE!

mobile page

12160.info/m

12160 Administrators

 

Latest Activity

Doc Vega posted photos
yesterday
Sandy posted a discussion
yesterday
Doc Vega commented on Burbia's blog post How much money makes anyone have a god complex?
"I seriously doubt Trump has a God complex as he is merely treying to save this country, but people…"
Tuesday
Sandy posted videos
Tuesday
Doc Vega posted photos
Monday
Doc Vega posted a blog post

Project Twinkle and an Incident at Holloman Air Force Base

    I didn’t think it would happen as soon as it did, but it did! I got the call and a black…See More
Monday
Less Prone posted a video

A teacher exposes the LGBT agenda coming into in elementary schools

At the Teens4Truth Conference at the Southwestern Baptist Theological Seminary, Nov.18, 2017. A teacher warns that parents have no idea how bad it is, and ev...
Sunday
Less Prone commented on Doc Vega's photo
Thumbnail

main-qimg-c0f46f334984bf2d4642651a38db08ca

"This is sick. What about learning something useful like, reading, mathematics, literature, science…"
Sunday
Burbia posted a blog post

How much money makes anyone have a god complex?

Trump makes a meme of himself as Jesus Christ. Soros says he fancied himself a sort of god.In 2004,…See More
Sunday
Sandy posted a photo
Saturday
Doc Vega posted a photo

main-qimg-c0f46f334984bf2d4642651a38db08ca

Hate children< then put them in a classroom where Lebians teach them how to use dildos, where…
Apr 24
Doc Vega commented on Doc Vega's blog post Why Was The TV Show “The Outer Limits” Such a Threat?
"Gordon thanks for your support."
Apr 23
Doc Vega posted a blog post

What If origins on Our Planet are Different Than we Think?

 For a long time now there has been a theory that would fit into both creationism and the simulated…See More
Apr 23
honeygirl posted a video

All Bases Erased, Air Defense Shattered ! Iranian Missiles Massacre U.S. FORCES | Douglas Macgregor

Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
Apr 23
Less Prone favorited Sandy's video
Apr 23
Less Prone favorited Doc Vega's blog post The Escape
Apr 23
Less Prone posted a photo

Same Package - Different Label

This way or that way, we get to the same place. It's time to take another road.
Apr 23
Less Prone favorited Sandy's video
Apr 23
agen Dadu is now a member of 12160 Social Network
Apr 23
Less Prone commented on tjdavis's photo
Thumbnail

TRIVIA OF THE DAY Kier means “Penis” in Persian

"Nomen est omen. A political dick destroying his own country."
Apr 23

© 2026   Created by truth.   Powered by

Badges  |  Report an Issue  |  Terms of Service

content and site copyright 12160.info 2007-2019 - all rights reserved. unless otherwise noted