On Saturday, December 26th, the US Computer Emergency Readiness Team (CERT) issued an alert for companies that use Solar Winds Orion software to apply a patch or mitigation to block access to vulnerable API endpoints and prevent unauthenticated remote code execution. This vulnerability can be exploited by any attacker and is not limited to the threat group responsible for the SUNBURST backdoor that was injected into the supply chain and discovered earlier this month. This vulnerability has apparently been exploited in the wild and is associated with the previously reported web shell known as SUPERNOVA, although it could be used to deliver other malicious payloads.
12 Essentials for a Successful SOC Partnership
As cyber threats continue to impact businesses of all sizes, the need for round-the-clock security