#1 - SolarWinds SUNBURST
The attack that proved a trusted software update is an attack vector
In 2020, the U.S. government, NATO, Microsoft, Cisco, FireEye, and 18,000 other organizations unknowingly installed a backdoor distributed as a routine, digitally signed software update from SolarWinds. The attackers had been inside SolarWinds build systems for over a year before the first trojanized update shipped.
SolarWinds.Orion.Core.BusinessLayer.dllTechnical detail
The attackers modified the CI build process so malicious code was compiled into the DLL and signed with SolarWinds legitimate certificate. SUNBURST included a 12-14 day dormancy period, DGA-based DNS calls to avsvmcloud[.]com, and checks that reduced exposure in security research environments. High-value victims received second-stage payloads enabling lateral movement, SAML token forgery against Azure AD, and data exfiltration through traffic that looked like Orion telemetry.
Impact
- 18,000 organizations downloaded the trojanized update
- Around 100 organizations were selected for follow-on operations
- Confirmed victims included U.S. federal agencies, NATO, the European Parliament, Microsoft, Intel, Cisco, and FireEye
- Remediation costs exceeded $100 million across affected entities
Aftermath
- Executive Order 14028 mandated SBOMs, zero-trust architecture, and enhanced logging for federal software
- The SEC action against SolarWinds leadership made cybersecurity disclosure a board-level liability issue
- The industry permanently changed its model: trusted update channels are attack surfaces