> Compromising and introducing a back door into a build environment such as TeamCity is the holy grail of a supply chain hack. It can allow an adversary to have thousands of SolarWinds-style back doors in all sorts of products in use by victims all over the world. This is a very big deal.
it read like this was much more widespread than I'm hearing now. The NY Times has even gone back and edited the title, replacing "Russian" with "widely used." I hope the editors have another take at this before it gets republished on all the other news sites ...
First, there's a WSJ article out now with some more details that appears to back him up[0]:
> Investigators believe that the SolarWinds hackers gained access to a TeamCity server used by SolarWinds to build its software products, but it is unclear how this system was accessed, according to people familiar with the matter.
Further, some rudimentary OSINT reserach indicates he is, in fact, a JetBrains employee. People can do their own sleuthing if they're inclined to verify this; I have no desire to dox the guy publicly.
[0]: https://www.wsj.com/articles/solarwinds-hack-breached-justic...