Emergency Directive 21-01: Mitigate SolarWinds Orion Code Compromise¶
Cybersecurity and Infrastructure Security Agency. (2020). Emergency Directive 21-01: Mitigate SolarWinds Orion Code Compromise: Mitigate SolarWinds Orion Code Compromise.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Trusted Intermediary Compromise
- The attacker write access is gained at the build server: the adversary inserts a backdoor into the source before it is compiled and signed, so the malicious build is signed by the legitimate key and is indistinguishable, to every downstream check, from a clean release.
This sourceDocuments the SolarWinds build-server compromise that shipped a signed trojan to thousands of customers.
- The attacker write access is gained at the build server: the adversary inserts a backdoor into the source before it is compiled and signed, so the malicious build is signed by the legitimate key and is indistinguishable, to every downstream check, from a clean release.
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:dca1fb6f9c76 · see in the full table