HT TECH wants to start sending you push notifications. Click allow to subscribe

SolarWinds’ security practices questioned by lawmakers following cyber attack

The cyber-attack was revealed in December after FireEye discovered it while investigating a breach of its own. The hackers implanted malicious code into SolarWinds’ popular Orion software, and as many as 18,000 customers received it while updating the software. 

By: BLOOMBERG
Updated on: Aug 21 2022, 15:15 IST
FILE PHOTO: The SolarWinds logo is seen outside its headquarters in Austin, Texas, U.S., December 18, 2020. REUTERS/Sergio Flores (REUTERS)

SolarWinds' security practices in the years leading up to a major cyber-attack by suspected Russian hackers, who leveraged the company’s software to infiltrate government agencies and private-sector companies, were questioned by lawmakers in Washington.

At a Friday hearing on the hack by two House committees, Representative Bennie Thompson, a Democrat from Mississippi and chairman of the Homeland Security Committee, asked SolarWinds representatives about reports of lax security at the company.

You may be interested in

Mobiles Tablets Laptops
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹156,900
Check details
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
Microsoft Surface Studio A1Y 00022
  • Platinum Silver
  • 16 GB LPDDR4X RAM
  • 512 GB SSD
₹209,990
Check details
7% OFF
Microsoft Surface Pro 8 8PV 00029
  • Graphite Black
  • 16 GB DDR4 RAM
  • 256 GB SSD
₹139,999₹149,999
Buy now
47% OFF
Microsoft Surface 4 5UI 00049
  • Platinum Silver
  • 8 GB DDR4 RAM
  • 256 GB SSD
₹98,000₹186,500
Buy now
Microsoft Surface Pro 7 M1866 VDH 00013
  • Platinum
  • 4 GB LPDDR4X RAM
  • 128 GB SSD
₹69,890
Check details
35% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹25,999₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,668₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹16,998
Check details

Kevin Thompson, who served as chief executive officer at the time of the breach, defended SolarWinds, saying it had beefed security in recent years and spent more than most technology companies of similar size.

“I believe that we have, over the history of time, taken security seriously -- security of our internal systems, and the secure development of our products,” said Thompson, the former SolarWinds CEO.

The cyber-attack was revealed in December after FireEye discovered it while investigating a breach of its own. The hackers implanted malicious code into SolarWinds’ popular Orion software, and as many as 18,000 customers received it while updating the software. Far fewer were actually targeted for secondary attacks -- about 100 companies and nine US agencies, according to the White House.

A persistent question has been how the hackers originally breached SolarWinds. At the hearing, SolarWinds CEO Sudhakar Ramakrishna said the company was still investigating but had narrowed it to three possible methods. 

The hackers may have used a technique called “password spraying,” where the attackers “spray” passwords at a large volume of usernames. A second possibility was that the hackers stole credentials, he said, while the third was a breach of a third-party application used by SolarWinds.

Also Read: SolarWinds, Microsoft, FireEye, CrowdStrike defend actions in major hack

Among the alleged security lapses at SolarWinds that were raised at the hearing was the use of the password “solarwinds123.” A cybersecurity researcher said he notified SolarWinds in 2019 that the password --- to one of its servers -- had leaked online.

In addition, lawmakers asked the SolarWinds representatives about a former security adviser who had recommended ways to improve cybersecurity and had stated that “the survival of the company depends on an internal commitment to security.”

The hearing was the second time this week that lawmakers heard from technology executives about the cyber-attack. Executives from cybersecurity companies and SolarWinds appeared before the Senate Intelligence Committee on February 23 -- at a hearing in which lawmakers criticised Amazon Web Services for failing to appear before the committee despite an invitation. AWS wasn’t invited to Friday’s hearing, according to a committee aide.

Representative Clay Higgins, a Republican from Louisiana, asked about reports the hackers used AWS servers to launch some of the attacks.

Also Read: SolarWinds hack was 'largest and most sophisticated attack' ever, says Microsoft prez

Brad Smith, the president of Microsoft and a witness at Friday’s hearing, responded by explaining the need for transparency about cyber-attacks, drawing a contrast between his company and Amazon. “I am here today. I am answering all your questions. Microsoft has published 32 blogs since this came to light. Amazon has yet to publish its first.”

An Amazon representative said the company wasn’t affected by “the SolarWinds issue” and didn’t use their software. The cyber-attack “demonstrated the security strengths of the cloud and the importance of modernizing legacy IT systems,” the representative said.

Bipartisan leaders of the Senate Intelligence Committee and technology executives who testified at the hearings called for a federal data breach notification law that would require companies to notify the federal government of cyber-attacks. Thompson, the chairman of the Homeland Security Committee, said at Friday’s hearing that he would support such a measure.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 27 Feb, 21:06 IST

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
11% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹79,800₹89,900
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
27% OFF
Samsung Galaxy Tab S8
  • Silver
  • 8 GB RAM
  • 128 GB Storage
₹59,999₹81,999
Buy now
21% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹88,858₹113,098
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
22% OFF
Asus ROG Strix G15 G513RC HN085WS Laptop
  • Electro Punk
  • 16 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now
30% OFF
Asus ROG Strix G15 G513QY HQ032WS Laptop
  • Original Black
  • 16 GB RAM
  • 1 TB SSD
₹79,990₹113,990
Buy now
33% OFF
Asus VivoBook Go 15 OLED E1504GA NJ323WS Laptop
  • Green Grey
  • 8 GB RAM
  • 512 GB SSD
₹33,990₹50,990
Buy now
NEXT ARTICLE BEGINS