Ad End 1 February 2024
Ad Ends 13 January 2025
Ad End 26 February 2025
ad End 25 April 2025
Ad Ends 20 January 2025
Ad expire at 5 August 2024
banner Expire 25 April 2025
What's new
banner Expire 15 January 2025
banner Expire 20 October 2024
UniCvv
casino
swipe store
adv exp at 23 August 2024
Carding.pw carding forum
BidenCash Shop
Kfc CLub

DHS, CISA and NCSC Issue Warnings After SolarWinds Attack

File_closed07

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 13, 2020
Messages
7,544
Reaction score
916
Points
212
Awards
2
  • trusted user
  • Rich User
Government agencies have issued warnings about the fresh spate of attacks, apparently from nation-state actors against major security vendors.

Last week FireEye disclosed that it had spotted an attack from nation state actors looking for data on government clients, where attackers were able to access some internal systems and steal some of FireEye’s red team tools. It was later disclosed that the attack was enabled by using trojanized updates to SolarWinds’ Orion IT monitoring and management software, although Solarwinds said that fewer than 18,000 of its global customers had been affected.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued Emergency Directive 21-01 in response to the SolarWinds compromise which calls “on all federal civilian agencies to review their networks for indicators of compromise and disconnect or power down SolarWinds Orion products immediately.”

In a statement, CISA acting director Brandon Wales said “the compromise of SolarWinds’ Orion Network Management Products poses unacceptable risks to the security of federal networks.”

He said: “Tonight’s directive is intended to mitigate potential compromises within federal civilian networks, and we urge all our partners—in the public and private sectors—to assess their exposure to this compromise and to secure their networks against any exploitation.”

Also, Alexei Woltornist, assistant secretary for public affairs at the Department of Homeland Security, said DHS is aware of cyber breaches across the federal government and working closely with its partners in the public and private sector on the federal response.

A spokesperson for the UK’s National Cybersecurity Centre (NCSC) said in a statement: “The NCSC is working closely with FireEye and international partners on this incident. Investigations are ongoing, and we are working extensively with partners and stakeholders to assess any UK impact. The NCSC recommends that organizations read FireEye’s update on their investigation and follow the company’s suggested security mitigations.”

It recommended organizations ensure any instances of SolarWinds Orion are configured according to the company’s latest guidance, and have these instances installed behind firewalls, disabling internet access for the instances, and limiting the ports and connections to only what are critically necessary.

Commenting, Sam Curry, chief security officer at Cybereason, said: “If 2020 has taught us anything, it is that the COVID-19 pandemic has improved the resiliency of security professionals and reinforced how determined defenders are to rid networks of cyber-espionage adversaries. In fact, all UK companies should respond with a cold, logical, rational response.

“In general, now is not the time for security experts to panic. A practical and measured response is advised.”

If SolarWinds is being used in your organization, Curry recommended strengthening your security posture as follows:
 
Ad End 1 February 2024
Top