🚨IR FOLKS - Look here🚨 - more in comments - If you are on a bridge right now... you need to jump on this GitHub... FireEye released signatures (Snort, YARA, and Clam) for Sunburst. These are all the detections they know of for the Solarwinds issue. https://github.com/fireeye/sunburst_countermeasures
Solarwinds Advisory that includes what versions are impacted and when hotfixes are coming - https://www.solarwinds.com/securityadvisory
FireEye says in their post if you can't complete the Solarwinds Recommendations do this -
Need the bullets?:
1. Crank logging of Solarwinds systems.
2. Kill outbound access from Solarwinds servers.
3. Magnifying glass on all outbound connectivity from sensitive segments.
4. Deploy detections now - https://github.com/fireeye/sunburst_countermeasures
1/x
5. Are you on a vulnerable version? - https://www.solarwinds.com/securityadvisory
6. Hotfix expected on 12/15 - If you are on a vulnerable version, get the your change request in now.
7. Start preparing to reset everyones access to Solarwinds AND every monitoring credential it uses.
2/x
11:19ish - CISA Tweet - https://twitter.com/USCERT_gov/status/1338337481654218753
Tomorrow (12/14) at 5pm ET - @MalwareJake will be summarizing what they know so far - https://sansurl.com/solarwinds 
An amazing break down from @KimZetter - https://twitter.com/KimZetter/status/1338305089597964290?s=20
More excellent analysis. Includes places to look for the malicious DLL. https://twitter.com/kylehanslovan/status/1338506923642122243
Solarwinds SEC filing - https://twitter.com/campuscodi/status/1338538285929541632
Veloxity write up on a group they called Dark Halo that seems to be the same threat actor.

https://www.volexity.com/blog/2020/12/14/dark-halo-leverages-solarwinds-compromise-to-breach-organizations/
You can follow @EanMeyer.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.