Russia's SolarWinds Attack
schneier.com
schneier.com
FireEye caught the compromise only because $Attacker went a little too far.
So one big lesson for any software shop that claims to be professional is to verify builds. It's clear that SloppyWinds is/was completely incompetent.
Whoever executed this compromise left nothing behind to indicate a country or linguistic group of origin. (For example, comments or characters of a certain alphabet or encoding.)
The perpetrator built the infrastructure patiently [1] and ran small tests before activating a select few of the implanted systems.
Small-time $Attackers don't usually show this much attention to the craft. There is skillful software development at work here.
[1] https://www.domaintools.com/resources/blog/unraveling-networ... , https://unit42.paloaltonetworks.com/solarstorm-supply-chain-...
>It wasn’t a cyberattack in international relations terms, it was espionage.
>Espionage is internationally allowed in peacetime.
If this was one of the many US espionage jobs against Russia or whatever nothing would be written about it except to yell "Tinfoil hat" or "Commie!".
All systems can and will be hacked should be your starting assumption. Your network is already hacked is the inescapable conclusion.
Given those assumptions, the focus should shift to data security. First, how is the integrity of the data protected? And second, how can you put the data out-of-reach from an intruder? If you are hacked, and the data is easy to reach, you have a severe vul.
In other words, while perimeter security is still necessary, your focus should shift to data security.