

Q: Are SolarWinds TFTP and SCP (tools available as free downloads) impacted?Ī: It is believed that only the SolarWinds Orion platform was affected by this supply chain attack.


Q: Is the attack similar to NotPetya in 2017?Ī: Yes, and recently we are finding that there are ties between the two. The code got inserted on their build server, in their build process as early as October 2019. Q: Is there any information from SolarWinds on how they were initially compromised?Ī: We don’t know, and as far as we have been tracking, they have not said. The questions below were asked by real Bitsight customers during a recent webinar surrounding the SolarWinds hack, and were answered by a Bitsight team made up of Stephen Boyer, Co-Founder and CTO, Jake Olcott, VP of Communications and Government Affairs, and Dan Dahlberg, Director of Security Research. The SolarWinds hack, discovered in late 2020 when FireEye announced it had been targeted through a third party vulnerability, has now become one of the most widespread and impactful supply chain attacks in history.Īs more information is gathered about where and when the SolarWinds hack originated and how security teams might have acted differently to prevent the hack, we asked our Bitsight experts to answer some of your most pressing SolarWinds questions.
