A Russian hacking campaign has struck several federal agencies, according to security companies and news reports.
Earlier this year, hackers compromised software made by a cybersecurity company you might not have heard of. The infiltration led to a massive malware campaignthat's now affecting US federal agencies as well as governments around the world, according to the security firm and news reports.
The hacked company, SolarWinds, sells software that lets an organization see what's happening on its computer networks. Hackers inserted malicious code into an updated version of the software, called Orion. Around 18,000 SolarWinds customers installed the tainted updates onto their systems, the company said.
Subscribe to CNET Now for the day's most interesting reviews, news stories and videos.
The compromised update process has had a sweeping effect, the scale of which keeps growing as new information emerges. Based on newspaper reports, the company's statements and analysis from other security firms, a Russian intelligence agency reportedly carried out a sophisticated attack that struck several US federal agencies and private companies including Microsoft.
On Saturday, President Donald Trump floated on Twitter the idea that China might be behind the attack. Trump, who didn't provide evidence to support the suggestion of Chinese involvement, tagged Secretary of State Mike Pompeo, who had earlier said in a radio interview that "we can say pretty clearly that it was the Russians that engaged in this activity."
US national security agencies issued a joint statement Wednesday acknowledging a "significant and ongoing hacking campaign" that's affecting the federal government. It's still unclear how many agencies are affected or what information hackers might have stolen so far, but by all accounts the malware is extremely powerful. According to analysis by Microsoft and security firm FireEye, both of which were also infected with the malware, it gives hackers broad reach into impacted systems.
On Thursday, Politico reported that systems at the Department of Energy and the National Nuclear Security Administration were also affected. Also on Thursday, Microsoft said it had identified more than 40 customers that were targeted in the hack. More information is likely to emerge about the hack and its aftermath. Here's what you need to know about the SolarWinds hack:
Hackers managed to access a system that SolarWinds uses to put together updates to its Orion product, the company explained in a filing with the SEC. From there, they inserted malicious code into otherwise legitimate software updates. This is known as a supply-chain attack, because it infects software while it's being assembled.
It's a big coup for hackers to pull off a supply-chain attack, because it packages their malware inside a trusted piece of software. Instead of having to trick individual targets into downloading malicious software with a phishing campaign, the hackers could rely on several government agencies and companies to install the Orion update at SolarWinds' prompting.
The approach is especially powerful in this case because hundreds of thousands of companies and government agencies around the world reportedly use the Orion software. With the release of the tainted software update, SolarWinds' vast customer list became potential hacking targets.
According to reports from Reuters, The Washington Post and TheWall Street Journal, the malware affected the US Homeland Security, State, Commerce and Treasury Departments, as well as the National Institutes of Health. Politico reported on Thursday that nuclear programs run by the US Department of Energy and the National Nuclear Security Administration were also targeted.
It's still unclear what information, if any, was stolen from the federal agencies, but the amount of access appears to be broad.
Though the Department of Energy and the Commerce Department have acknowledged the hacks to news sources, there's no official confirmation that other specific federal agencies have been hacked. However, the US Cybersecurity and Infrastructure Security Agency put out an advisory urging federal agencies to mitigate the malware, noting that it's "currently being exploited by malicious actors."
In a statement Thursday, President-elect Joe Biden said his administration will "make dealing with this breach a top priority from the moment we take office."
In addition to gaining access to several government systems, the hackers turned a run-of-the-mill software update into a weapon. That weapon was pointed at thousands of groups, not just the agencies and companies that the hackers focused on after they installed the tainted Orion update.
Microsoft president Brad Smith called this "an act of recklessness" in a wide-ranging blog post that explored the ramifications of the hack. He didn't directly attribute the hack to Russia, but described its previous alleged hacking campaigns as proof of an increasingly fraught cyber conflict.
"This is not just an attack on specific targets," Smith said, "but on the trust and reliability of the world's critical infrastructure in order to advance one nation's intelligence agency." He went on to call for international agreements to limit the creation of hacking tools that undermine global cybersecurity.
Former Facebook cybersecurity chief Alex Stamos said on Twitter that the hack could lead to supply-chain attacks becoming more common. However, he questioned whether the hack was anything out of the ordinary for a well resourced intelligence agency.
"So far, all of the activity that has been publicly discussed has fallen into the boundaries of what the US does regularly," Stamos said.
Yes. Microsoft confirmed Thursday that it found indicators of the malware in its systems, after confirming Sunday that the breach was affecting customers of its cybersecurity services. A Reuters report also said that Microsoft's own systems were used to further the hacking campaign, but Microsoft denied this claim to news agencies. On Wednesday, the company began quarantining the versions of Orion known to contain the malware, in order to cut hackers off from its customers' systems.
FireEye also confirmed last week that it was infected with the malware and was seeing the infection in customer systems as well.
Other than FireEye and Microsoft, it isn't clear which of SolarWinds' private sector customers saw malware infections. The company's customer list includes large corporations, such as AT&T, Procter & Gamble and McDonald's. The company also counts governments and private companies around the world as customers. FireEye says many of those customers were infected.
Unnamed US government officials have reportedly told news outlets that a hacking group widely believed to be a Russian intelligence agency is responsible for the malware campaign. SolarWinds, cybersecurity firms and US government statements have attributed the hack to "nation-state actors" but haven't named a country directly.
In a statement on Facebook, the Russian embassy in the US denied responsibility for the SolarWinds hacking campaign. "Malicious activities in the information space contradict the principles of the Russian foreign policy, national interests and our understanding of interstate relations," the embassy said, adding, "Russia does not conduct offensive operations in the cyber domain."
Nicknamed APT29 or CozyBear, the hacking group named by news reports has previously been blamed for targeting email systems at the State Department and White House during the administration of President Barack Obama. It was also named by US intelligence agencies as one of the groups that infiltrated email systems at the Democratic National Committee in 2015, but the leaking of those emails isn't attributed to CozyBear. (Another Russian agency was blamed for that.)
More recently, the US, UK and Canada have identified the group as responsible for hacking efforts that tried to access information about COVID-19 vaccine research.
The rest is here:
Microsoft head calls SolarWinds hack 'act of recklessness': What you need to know - CNET
- Protect Your Home Title & Equity from Fraud with TripleLock Monitoring, Alerts & Restoration - ABC Action News Tampa Bay - November 12th, 2024 [November 12th, 2024]
- Wireless Home Security Camera Market is growing at a CAGR of 20% in the forecast period (2024-2031) - openPR - November 12th, 2024 [November 12th, 2024]
- Yes, Smart Homes Are Vulnerable to Cybercriminals. Here's What You Need to Know. - House Beautiful - November 12th, 2024 [November 12th, 2024]
- Limited-Time Deal: Protect Your Home or Business With a Ring Indoor Camera at Almost 40% Off - CNET - November 12th, 2024 [November 12th, 2024]
- The 3 Best Indoor Security Cameras of 2024 | Reviews by Wirecutter - Wirecutter, A New York Times Company - November 12th, 2024 [November 12th, 2024]
- Get home security cameras up to 60% off and feel extra cozy this winter - Mashable - November 12th, 2024 [November 12th, 2024]
- Resideo Unveils Honeywell Home FocusPRO Thermostats - SecurityInformed - November 12th, 2024 [November 12th, 2024]
- A Smart Before-the-Holidays Decision: Arlo and Allstate are Boosting Peace of Mind with New Home Security Bundle - IoT Evolution World - November 12th, 2024 [November 12th, 2024]
- The Google Nest Cam With Floodlight Is at Its Lowest Ever Price, but Not for Long - CNET - November 12th, 2024 [November 12th, 2024]
- Man shot by security guard at Home Depot in Northeast Philly - The Philadelphia Inquirer - November 12th, 2024 [November 12th, 2024]
- Keep Eyes on Your Home at All Times With a Blink Outdoor Cam for 60% Off - CNET - November 12th, 2024 [November 12th, 2024]
- A Letter to the Nation's New Leaders: Right Now, the American Dream of Homeownership Is in Crisis - SFGATE - November 12th, 2024 [November 12th, 2024]
- Get your tickets SECURED to Z100s Jingle Ball from Slomins Home Security! - iHeart - November 12th, 2024 [November 12th, 2024]
- We test a new home security package that couldn't be simpler to install - The Scotsman - November 12th, 2024 [November 12th, 2024]
- 6 Smart Gadgets That Will Instantly Upgrade Any Home's Lighting And Security - SlashGear - November 12th, 2024 [November 12th, 2024]
- Amazon has this Blink doorbell and security camera bundle on sale for the lowest price ever and its before - NJ.com - September 29th, 2024 [September 29th, 2024]
- This Blink Video Doorbell and security camera bundle is down to $59.99 at Amazon - TechRadar - September 29th, 2024 [September 29th, 2024]
- This new Eufy home security camera uses AI to add color to its night vision - TechRadar - September 29th, 2024 [September 29th, 2024]
- Did Jennifer Lopez and Ben Affleck Just Run Into More Trouble With Sale of $68 Million Marital Mansion? - SFGATE - September 29th, 2024 [September 29th, 2024]
- Sound the alarm! This 14-piece Ring smart security system is 40% off - Android Police - September 29th, 2024 [September 29th, 2024]
- Ring's Pan-Tilt Indoor Camera Just Crashed to a New Amazon Low Ahead of Prime Day - CNET - September 29th, 2024 [September 29th, 2024]
- The best home security cameras 2024: the smartest way to protect your home - TechRadar - September 29th, 2024 [September 29th, 2024]
- Bump Up Your Home Security With the Ultraloq Smart Lock for Only $99 - CNET - September 29th, 2024 [September 29th, 2024]
- This Early Prime Day Deal Will Score You a Blink Outdoor Camera for Over Half Off - CNET - September 29th, 2024 [September 29th, 2024]
- Supermodel Elle Macpherson Finally Sells Artsy Mansion at a Steep Discount After 2 Years on the Market - SFGATE - September 29th, 2024 [September 29th, 2024]
- Home security cameras: Learn how and where to install them for optimal protection - CNN Underscored - September 20th, 2024 [September 20th, 2024]
- Lions Dan Campbell has home address doxxed, creating series of security concerns - FOX 2 Detroit - September 20th, 2024 [September 20th, 2024]
- 2024's Best Outdoor Cameras: Vetted by Security Experts - Security.org - September 20th, 2024 [September 20th, 2024]
- Chilling home security footage shows what teen did seconds after 'fatally shooting her mother' - UNILAD - September 20th, 2024 [September 20th, 2024]
- Smart Home Security Camera Market is Expected to See a Growth of 13.2% CAGR from 2024 to 2034 | FMI - Future Market Insights - September 20th, 2024 [September 20th, 2024]
- Best Buy Deals of The Day: Save at Least $100 on Headphones, Home Security Systems, and Routers - PCMag - September 7th, 2024 [September 7th, 2024]
- How to Protect Your Outdoor Security Cameras During Stormy Weather, According to Experts - Bob Vila - September 7th, 2024 [September 7th, 2024]
- Protecting your home costs a mere $100 with this awesome Arlo setup - TechHive - September 7th, 2024 [September 7th, 2024]
- Breaking Home Security Myths: United Locksmith Keeps Houston Safe with Expert Services - openPR - September 7th, 2024 [September 7th, 2024]
- Master Locks Folding Door Security Bar Offers Cheap and Effective Home Security - Bob Vila - September 7th, 2024 [September 7th, 2024]
- Home security cameras capture father's panic after he pulls his unresponsive toddler from pool - ABC Action News Tampa Bay - September 7th, 2024 [September 7th, 2024]
- Reolink shines at IFA 2024 with major rebranding and groundbreaking new products - BGR - September 7th, 2024 [September 7th, 2024]
- Four gunshots fired in area of SW Redmond; police go door-to-door seeking witnesses, home security videos - KTVZ - September 7th, 2024 [September 7th, 2024]
- Some of Our Favorite Ring Security Cams Are Down to New Lows at Woot - CNET - September 7th, 2024 [September 7th, 2024]
- "I feel like I'm in Big Brother" the trouble with home security cameras! - Digital Camera World - September 7th, 2024 [September 7th, 2024]
- The Best Home Security Cameras and Systems for Off-the-Grid Living in 2024 - CNET - September 7th, 2024 [September 7th, 2024]
- Smith Thompson Home Security and Alarm Austin Highlights the Importance of Fire Safety Equipment in Protecting - EIN News - September 7th, 2024 [September 7th, 2024]
- Alfred DB2S: Advanced Home Security With RFID And Z-Wave - SecurityInformed - September 7th, 2024 [September 7th, 2024]
- The waterproof Blink Mini 2 security camera is the best Wyze Cam alternative available - ZDNet - September 7th, 2024 [September 7th, 2024]
- Digital Projection Unveils Radiance Home Video Wall At CEDIA Expo 2024 - SecurityInformed - September 7th, 2024 [September 7th, 2024]
- Secure your whole home with this half-off Arlo three-cam bundle - TechHive - September 7th, 2024 [September 7th, 2024]
- Best home security cameras 2024: Reviews and buying advice - TechHive - August 17th, 2024 [August 17th, 2024]
- 6 Ways to Stop Your Home Security Camera From Being Hacked - CNET - August 17th, 2024 [August 17th, 2024]
- Top Home Security Tips When You're Renting with Roommates - CNET - August 17th, 2024 [August 17th, 2024]
- Cicero Police: Looking for home security video following neighborhood thefts from cars - WSYR - August 17th, 2024 [August 17th, 2024]
- The first U.S. metro to hit $2M median home price is, of course, in the Bay Area - SFGATE - August 17th, 2024 [August 17th, 2024]
- Burglaries Spike in This California CityTips To Keep Your Home From Being the Next Target - Realtor.com News - August 17th, 2024 [August 17th, 2024]
- Smart Home Innovations 2024: Trends in AI, Security, and Sustainability - TechBullion - August 17th, 2024 [August 17th, 2024]
- Beyond the eye-popping sum, this could violate the Texas Open Meetings Act - The Dallas Express - August 17th, 2024 [August 17th, 2024]
- Zumi Introduces Advanced Gate Openers for Greater Home Security in the United States - Kirkland Lake Northern News - August 17th, 2024 [August 17th, 2024]
- Home security video in Euclid appears to show debris being thrown into Lake Erie - Cleveland 19 News - August 4th, 2024 [August 4th, 2024]
- Her Security Cameras Show Her Family Breaking Things And Hurting Her Dog, So She Ends Their Visit Early And Tells Them To Never Come Back - Twisted... - August 4th, 2024 [August 4th, 2024]
- Sarah Hyland catches live burglary of her home while out of town - The News International - August 4th, 2024 [August 4th, 2024]
- Amazon just slashed the price of our favorite budget home security camera - Tom's Guide - March 14th, 2024 [March 14th, 2024]
- Los Angeles Police Department warning home owners to hard-wire home security systems as organized theft rings ... - Notebookcheck.net - March 14th, 2024 [March 14th, 2024]
- Best Security Systems For Apartments Of 2024 Forbes Home - Forbes - March 14th, 2024 [March 14th, 2024]
- Airbnb's Unexpected Home Security Ban Sets A New Standard For Rental Property Owners - House Digest - March 14th, 2024 [March 14th, 2024]
- Best home security deal: Get the Arlo Essential Wired Video Doorbell for just $49.99 at Amazon. - Mashable - March 14th, 2024 [March 14th, 2024]
- Lithe Audio and Lilin integrate AI for home security - HiddenWires - March 14th, 2024 [March 14th, 2024]
- Why Airbnb Is Banning Cameras in Rentals - TIME - March 14th, 2024 [March 14th, 2024]
- Best Home Security Cameras of 2024 - CNET - February 16th, 2024 [February 16th, 2024]
- Blink's video doorbell just crashed to $44 and it doesn't require a subscription - Tom's Guide - February 16th, 2024 [February 16th, 2024]
- Snag Up to 43% off These Blink Security Cameras and Doorbells - CNET - February 16th, 2024 [February 16th, 2024]
- U.S. House Republicans impeach Homeland Security chief Mayorkas on second try Oregon Capital Chronicle - Oregon Capital Chronicle - February 16th, 2024 [February 16th, 2024]
- Wi-Fi jamming to knock out cameras suspected in nine Minnesota burglaries -- smart security systems vulnerable as ... - Tom's Hardware - February 16th, 2024 [February 16th, 2024]
- The 4 Best Security Cameras for Your Home of 2024 | Reviews by Wirecutter - The New York Times - February 16th, 2024 [February 16th, 2024]
- The 4 Best Smart Doorbell Cameras of 2024 | Reviews by Wirecutter - The New York Times - February 16th, 2024 [February 16th, 2024]
- Vory Threatens To 'Kill' Girlfriend In Alleged Footage Of Domestic Abuse - HipHopDX - February 16th, 2024 [February 16th, 2024]
- Best Smart Locks of 2024 - CNET - February 16th, 2024 [February 16th, 2024]
- The Ring Battery Doorbell Pro has 3D motion detection - Gadget Flow - February 16th, 2024 [February 16th, 2024]
- Ring Is Raising Rates on Some Plans by 25% in March - PCMag Middle East - February 16th, 2024 [February 16th, 2024]
- The 12 Best Home Security Cameras of 2023 - Security.org - December 11th, 2023 [December 11th, 2023]
- Traveling for the holidays? Keep an eye on your home with the Blink Mini security camera, now just $20 - Gwinnettdailypost.com - December 11th, 2023 [December 11th, 2023]
- Gangs from South America use security jammers to break in to expensive homes across country: police - WLS-TV - December 11th, 2023 [December 11th, 2023]
- Best Home Security Companies Of 2023 Forbes Home - Forbes - December 11th, 2023 [December 11th, 2023]