Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Yo_Mama_Been_Loggin

(135,729 posts)
Mon Dec 21, 2020, 06:42 PM Dec 2020

SolarWinds hack hits major tech companies and hospital system: What you need to know

A Russian intelligence agency is carrying out a sophisticated malware campaign, striking several US federal agencies and private companies including Microsoft, according to the State Department, news reports and analysis from security firms. It all started earlier this year, when hackers compromised software made by cybersecurity SolarWinds.

The hacked company sells software that lets an organization see what's happening on its computer networks. Hackers inserted malicious code into an updated version of the software, called Orion. Around 18,000 SolarWinds customers installed the tainted updates onto their systems, the company said. The compromised update process has had a sweeping effect, the scale of which keeps growing as new information emerges.

On Saturday, President Donald Trump floated on Twitter the idea that China might be behind the attack. Trump, who didn't provide evidence to support the suggestion of Chinese involvement, tagged Secretary of State Mike Pompeo, who had earlier said in a radio interview that "we can say pretty clearly that it was the Russians that engaged in this activity."

US national security agencies issued a joint statement Wednesday calling it a "significant and ongoing hacking campaign" that's affecting the federal government. It's still unclear how many agencies are affected or what information hackers might have stolen so far, but by all accounts the malware is extremely powerful. According to analysis by Microsoft and security firm FireEye, both of which were also infected with the malware, it gives hackers broad reach into impacted systems.

On Thursday, Microsoft said it had identified more than 40 customers that were targeted in the hack. More information is likely to emerge about the hack and its aftermath. Here's what you need to know about the SolarWinds hack:

-more-

https://www.cnet.com/news/solarwinds-hack-hits-major-tech-companies-and-hospital-system-what-you-need-to-know/?ftag=CAD-04-10abf6e&bhid=24447454298893839703959737945916&mid=13207131&cid=534320049

8 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
SolarWinds hack hits major tech companies and hospital system: What you need to know (Original Post) Yo_Mama_Been_Loggin Dec 2020 OP
What is Putin's goal with the hack? He is an evil diabolic genius with unlimited funds. Irish_Dem Dec 2020 #1
Most of your Open-Source Software is malware or infused with vulnerabilities and back doors. TheBlackAdder Dec 2020 #2
I thought Putin wishing Biden "every success" was ominous. CrispyQ Dec 2020 #3
Yes that is creepy isn't it, coming from Putin. Irish_Dem Dec 2020 #4
Putin is going to regret this. StClone Dec 2020 #5
I would cut all fiber going into Russia if I were President. roamer65 Dec 2020 #6
Wish we could do more snip snip than fiber. nt Irish_Dem Dec 2020 #7
I hear ya. roamer65 Dec 2020 #8

Irish_Dem

(81,277 posts)
1. What is Putin's goal with the hack? He is an evil diabolic genius with unlimited funds.
Mon Dec 21, 2020, 06:45 PM
Dec 2020

I don't think he was just going fishing.

TheBlackAdder

(29,981 posts)
2. Most of your Open-Source Software is malware or infused with vulnerabilities and back doors.
Mon Dec 21, 2020, 06:52 PM
Dec 2020

.

Many in IT were saying how secure Open-Source Software is because many people review the code, when in reality everyone assumes other people are reviewing it and most of the people detecting vulnerabilities are hackers, nation-state actors and the occasional college academic.

On top of that, hackers have infiltrated most of the Open-Source projects to inject their vulnerabilities.

So, when people grab that free piece of software, thinking they are saving money, they are really just opening up their systems for intrusion and abuse.

.

CrispyQ

(40,970 posts)
3. I thought Putin wishing Biden "every success" was ominous.
Mon Dec 21, 2020, 07:06 PM
Dec 2020

He'll wait until after Biden is sworn in before he stirs up any mischief.

Irish_Dem

(81,277 posts)
4. Yes that is creepy isn't it, coming from Putin.
Mon Dec 21, 2020, 07:22 PM
Dec 2020

I think he could threaten Biden: "nice little nuclear stockpile there you have Joe, hate for anything to happen it."

StClone

(11,869 posts)
5. Putin is going to regret this.
Mon Dec 21, 2020, 07:28 PM
Dec 2020

For now it seems we will be vulnerable as the malware is installed in places, hidden, inactive and set to steal data, corrupt files, or disrupt or disable systems through the country. Slowly we will weed it out.

We will learn from this and the system will come back stronger but there are always vulnerabilities. Russia is now very much a pariah throughout the world. The Biden administration will build goodwill and cooperation to go tough on Putin. I'd love to squeeze the ba jesus out of that rat'fer in every way possible. It is going to get rough for Pooty. Already many RU addresses are being shut down on the internet without Biden already in charge. Watch this space.

Latest Discussions»General Discussion»SolarWinds hack hits majo...