CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

The SolarWinds Attack

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1843

As cited

Copy frozen at (site build).

breaches incidents

The SolarWinds Attack

The SolarWinds supply chain compromise, discovered in December 2020, involved attackers injecting malicious code into legitimate software updates from the IT management vendor SolarWinds, affecting thousands of organizations including U.S. government agencies. The attack demonstrated how trusted software distribution channels can be weaponized to achieve widespread access and persistence. This incident became a watershed moment for understanding supply chain risk and the need for enhanced software integrity controls.

Why it matters: Organizations using SolarWinds Orion and other products need to understand how supply chain compromises bypass traditional perimeter defenses; this attack affected critical infrastructure operators, federal agencies, and enterprises, making it relevant to any practitioner managing software inventory and vendor risk today.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

The SolarWinds Attack

Wiz CTO Ami Luttwak provided an explanation of the SolarWinds supply chain attack, which compromised multiple US government agencies and private organizations through trojanized software updates. The incident affected thousands of organizations worldwide and led to heightened scrutiny of software supply chain security practices.

Why it matters: Organizations relying on SolarWinds Orion platform need to assess their exposure to the compromise and implement detection controls, while practitioners should review third-party software update processes as a critical attack surface.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

The SolarWinds Attack

Wiz CTO Ami Luttwak provided an explanation of the SolarWinds supply chain attack, which compromised multiple US government agencies and private organizations through trojanized software updates. The incident affected thousands of organizations worldwide and led to heightened scrutiny of software supply chain security practices.

Why it matters: Organizations relying on SolarWinds Orion platform need to assess their exposure to the compromise and implement detection controls, while practitioners should review third-party software update processes as a critical attack surface.

VendorsSolarWinds
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary