December 13, 2020
SolarWinds supply-chain hack disclosed
FireEye disclosed on December 13, 2020 that nation-state actors had compromised SolarWinds Orion software — inserting backdoorA hidden way to access a system bypassing normal security — often installed by attackers or left by developers. code into updates trusted by thousands of organizations.
What it was for
The SUNBURST trojan rode signed Orion builds into U.S. government agencies, MicrosoftThe software giant behind Windows, Office, Azure, and Xbox — founded by Bill Gates and Paul Allen., and Fortune 500 networks — the definitive supply-chain breach. DevOpsPractices combining software development and IT operations — automation, CI/CD, and faster releases. teams accelerated SBOM adoption, build-pipeline signing, and least-privilege for CI/CDCompact disc — an optical storage format for digital audio and data. — treating dependency and vendor updates as attack surfaces, not chores.
Why it's here
SolarWinds was the supply-chain compromise that made every vendor update suspect.
Why it mattered
It forced SBOMs, signed builds, and zero-trust into mainstream DevSecOps.
What it solved
Nothing initially — attackers piggybacked on trusted auto-update channels.
Media
ImageScreensaver SolarwindsScreensaver author, screenshot by me, CC BY-SA 3.0, via wikimedia
Related
- Stuxnet worm discovered targeting industrial systemsJune 17, 2010
- Log4Shell vulnerability disclosedDecember 9, 2021
- Heartbleed OpenSSL vulnerability disclosedApril 7, 2014