“Highly Evasive Attacker Leverages SolarWinds "Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor”… some of you may have seen this news by now.
In my previous post, I had written about how the software supply chain is being increasing targeted by bad actors.
This is what is known at this point…
"SolarWinds.Orion.Core.BusinessLayer.dll is a SolarWinds digitally-signed component of the Orion software framework that contains a backdoor that communicates via HTTP to third party servers. We are tracking the trojanized version of this SolarWinds Orion plug-in as SUNBURST."
For those of you who are non-technical, a .dll file is a compiled code library.
This is making me think how important security has become at the stage of compilation and building software. Specially with all the CI/CD workflows growing at an exponential rate. The onus on the developer to ensure security is even more important now.
So, it’s nice to see developments like these from DDOG moving in the right direction…
"The Datadog action continuously monitors dependency and version information of code being deployed. By integrating this data with Datadog’s Continuous Profiler and Snyk’s Vulnerability database, this provides a real-time view of what code is actually accessible and vulnerable in production.
Scanning applications for known vulnerabilities often yields a long list of issues that are difficult to prioritize and subsequently fix. With the data collected by the new action, vulnerability analysis will be performed by the Datadog Continuous Profiler based on Snyk vulnerability metadata.
This allows engineering teams to immediately detect when and how often vulnerable methods are invoked in live environments and prioritize their security fixes based on real-world application behavior."
If you’re interested read more here: https://www.helpnetsecurity.com/2020/12/14/datadog-vulnerabi…
As I write this there’s news that DHS has also been compromised alongside Treasury and Commerce depts…
https://www.reuters.com/article/us-global-cyber-usa-dhs/susp…
So, I counting more on CRWD and DDOG to use the information from these hacks to help take security to the next level.
Cheers!
ronjonb