"Solarwinds123": Hacked IT Company Used Weak Password, While Backdoor Access Peddled On Underground Forums

"Solarwinds123": Hacked IT Company Used Weak Password, While Backdo...


Tyler Durden's Photo
BY TYLER DURDEN
WEDNESDAY, DEC 16, 2020 - 10:00

Hacked Texas-based IT infrastructure provider SolarWinds was warned over weak password security last year, after security researcher Vinoth Kumar discovered that the company used "solarwinds123" to protect their update server.

"This could have been done by any attacker, easily," said Kumar, according to Reuters.

On Monday, SolarWinds confirmed that their flagship network management software, Orion, was the target of an international cyberespionage operation which the Washington Post pinned on government-backed Russian hackers - who inserted malicious code into Orion software updates and pushed it out to almost 18,000 customers. 

The malicious updates - sent between March and June, when America was hunkering down to weather the first wave of coronavirus infections - was “perfect timing for a perfect storm,” said Kim Peretti, who co-chairs Atlanta-based law firm Alston & Bird’s cybersecurity preparedness and response team.

Assessing the damage would be difficult, she said.

We may not know the true impact for many months, if not more – if not ever,” she said. -Reuters

Included in the breach were the US Treasury, the Commerce Department's National Telecommunications and Information Administration (NTIA) and other government agencies.

Meanwhile, Reuters also reports that "multiple criminals have offered to sell access to SolarWinds’ computers through underground forums, according to two researchers who separately had access to those forums."

One of those offering claimed access over the Exploit forum in 2017 was known as “fxmsp” and is wanted by the FBI “for involvement in several high-profile incidents,” said Mark Arena, chief executive of cybercrime intelligence firm Intel471. Arena informed his company’s clients, which include U.S. law enforcement agencies. -Reuters

According to the report, neither the weak password or the stolen access are considered the most likely source of the current intrusion, however Kyle Hanslovan, the cofounder of Maryland-based cybersecurity company Huntress, noticed days after the SolarWinds hack that malicious updates were still available for download.

Dominion?

On Monday, screenshots began floating around of Dominion Voting Systems with a solarwinds logo below a login screen, implying that the 2020 US election may have been compromised by hackers, as opposed to on purpose as Trump and his allies have claimed.

Journalist Kim Zetter, however, pointed out that while Dominion does or did use a SolarWinds product, it wasn't their Orion software which was compromised. 

The company's stock has fallen over 25% since Friday's price of $23.50, currently sitting below $18. The company announced on December 9 that CEO Kevin Thompson would be replaced after 11 years at the helm with Sudhakar Ramakrishna, the former CEO of Pulse Secure.

Views: 23

Comment

You need to be a member of 12160 Social Network to add comments!

Join 12160 Social Network

"Destroying the New World Order"

TOP CONTENT THIS WEEK

THANK YOU FOR SUPPORTING THE SITE!

mobile page

12160.info/m

12160 Administrators

 

Latest Activity

Doc Vega posted a blog post

Donald Trump Gives an Amazing Speech on Freeing America from the Stranglehold of the Deep State

President Trump gives an amazing speech addressing all major challenges to restoring the…See More
16 hours ago
Doc Vega commented on Doc Vega's blog post What Will happen When Robot Brides Replace Human Marriage?
"Less Prone thanks for your support Buddy! "
16 hours ago
Less Prone favorited tjdavis's video
yesterday
Less Prone posted a photo

Social Engineering 101

That's how it goes.
yesterday
Doc Vega posted a blog post

A Prelude to WW III ? It Seems There We Are Trailblazing Idiocy into More Blood and Destruction!

They're rolling out the 25th Amendment trying to stop Joe Biden from insanely thrusting the US in a…See More
yesterday
Less Prone posted a video

Chris Langan - The Interview THEY Didn't Want You To See - CTMU [Full Version; Timestamps]

DW Description: Chris Langan is known to have the highest IQ in the world, somewhere between 195 and 210. To give you an idea of what this means, the average...
Wednesday
Doc Vega posted a blog post

RFK Jr. Appoinment Rocks the World of the Federal Health Agncies and The Big Pharma Profits!

The Appointment by Trump as Secretary of HHS has sent shockwaves through the federal government…See More
Tuesday
tjdavis posted a video

Somewhere in California.

Tom Waites and Iggy Pop meet in a midnight diner in Jim Jarmusch's 2003 film Coffee and Cigarettes.
Tuesday
cheeki kea commented on cheeki kea's photo
Thumbnail

1 possible 1

"It's possible, but less likely. said the cat."
Monday
cheeki kea posted a photo
Monday
tjdavis posted a blog post
Monday
Tori Kovach commented on cheeki kea's photo
Thumbnail

You are wrong, all of you.

"BECAUSE TARIFFS WILL PUT MONEY IN YOUR POCKETS!"
Monday
Tori Kovach posted photos
Monday
Doc Vega posted a blog post

Whatever Happened?

Whatever Happened?  The unsung heroes will go about their dayRegardless of the welcome they've…See More
Sunday
Doc Vega commented on Doc Vega's blog post A Requiem for the Mass Corruption of the Federal Government
"cheeki kea Nice work! Thank you! "
Sunday
cheeki kea commented on Doc Vega's blog post A Requiem for the Mass Corruption of the Federal Government
"Chin up folks, once the low hanging fruit gets picked off a clearer view will reveal the higher…"
Nov 16
Doc Vega's 4 blog posts were featured
Nov 16
tjdavis's blog post was featured
Nov 16
cheeki kea commented on cheeki kea's blog post Replicon Started in Tokyo October 08, 2024
"Your right LP it's insane for sure and hopefully improbable, keeping an open mind. Checking…"
Nov 16
rlionhearted_3 commented on tjdavis's blog post Bill Gates Deleted Documentary
Nov 16

© 2024   Created by truth.   Powered by

Badges  |  Report an Issue  |  Terms of Service

content and site copyright 12160.info 2007-2019 - all rights reserved. unless otherwise noted