Atlantic Councils Cyber Statecraft Initiative on Sunburst and SolarWinds
Summary
“The kind of access to federal networks including Commerce, Treasury, DHS, and DoD, that has been described would provide insight on strategic decision-making, advance warning of sanctions, and rulemaking. While no one has yet publicly reported there was a compromise of classified networks, what attackers appear to have had would effectively be a means to read the mind of an organization, comparable to well-placed human intelligence sources. “This doesn’t suggest Office365 is radically less secure than competitors; the 2019 Capital One data breach was partly a result of failures to properly configure, monitor, and manage the complex identity and authentication tools provided by Amazon Web Services. It does suggest cloud security should not be taken as guaranteed and deserves more scrutiny from policymakers and large cloud customers and transparency from vendors.” Key Takeaways from Breaking Trust: Shades of Crisis Across an Insecure Software Supply Chain (July 2020): · Attacks on software updates are especially pernicious because they undermine user’s trust in a key channel for updates and security fixes. Hijacked updates remained a consistently popular way to attack software supply chains over the last 10 years despite industry efforts to secure them.