FLASH: "Emergency Directive 21-01 calls on all federal civilian agencies to review their networks for indicators of compromise and disconnect or power down SolarWinds Orion products immediately."-@CISAgov Read more: cisa.gov/news/2020/12/1…
CONTD: @CISAgov is responding to an exploit of Federally operated @solarwinds Orion products by malicious actors. They Issued an Emergency Directive to federal civilian agencies to review networks & DISCONNECT OR POWER DOWN ALL SOLARWINDS ORION PRODUCTS NOW!
CONTD: @FireEye discovered an attack trojanizing @solarwinds Orion biz software distributing malware named #SUNBURST.
The attacker’s use multiple techniques to evade detection/obscure activity. The campaign is widespread affecting public & private organizations around the world.
CONTD: The trojan version of a @SolarWinds Orion plug-in codename #SUNBURST. After a dormant period of up to 2 weeks, it retrieves & executes commands including transfering files, executing files, profile the system, reboot, & disable system services.... more
CONTD: #SUNBURST hides network traffic & stores recon within legitimate plugin configuration files allowing it to blend in with legitimate activity. The backdoor uses obfuscated blocklists to i.d. forensic & anti-virus tools running as processes, services, & drivers.... more
CONTD: Worldwide Victims With #SUNBURST Distributed March thru May 2020. @FireEye has detected this malware in government, consulting, tech, telecom & extractive entities in North America, Europe, Asia & the Middle East & anticipate there are additional victims.... more
CONTD: After #SUNBURST gains access the attacker group disguise their operations moving laterally in the compromised network. The attacker maintains a light malware footprint, instead preferring legitimate credentials & remote access for access through the victim’s environment.
CONTD: If @SolarWinds infrastructure is not isolated:
-Restrict scope of connectivity to endpoints from SolarWinds servers!
-Restrict the scope of accounts that have local administrator privileged on SolarWinds servers!
.... more
CONTD: If @solarwinds infrastructure is not isolated:
-Block Internet egress from servers or other endpoints with SolarWinds software.
-At MINIMUM changing passwords for accounts that have access to SolarWinds servers / infrastructure.
....more
CONTD: If @solarwinds manages networking infrastructure:
-Review network device configurations for unexpected / unauthorized modifications. This is a proactive measure due to the scope of SolarWinds functionality.
CONTD: @SolarWinds’ Customers;
-425+ of US Fortune 500 co's
-All of top 10 US telecom co's
-All 5 branches US Military
-Pentagon
-State Department
-NASA
-NSA
-USPS
-NOAA
-DOJ
-Office of POTUS
-Top 5 US accounting firms
-100's universities/colleges
List: solarwinds.com/company/custom…

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with John Basham 🇺🇲

John Basham 🇺🇲 Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @JohnBasham

14 Dec
FLASH: @YouTube DOWN WORLDWIDE...DEVELOPING! Image
UPDATE: OUTAGE APPEARS TO AFFECT MOST @Google SERVICES AS WELL AS THOSE RELYING ON THE GOOGLE BACKBONE!
@downdetector SHOWING SUDDEN SPIKE ACROSS INTERNET IN OUTAGES...DEVELOPING... Image
UPDATE: The Outage Doesn't Appear To Be Affecting 100% Of Users, But Does Appear Massive & Worldwide At This Time!...DEVELOPING...
Read 8 tweets
16 Nov
BREAKING: A Supply Chain Software Attack Is Happening Worldwide, Including The U.S., Right Now! The Apparent Malware Attack Effects Software At Supply Chain Distribution Centers. This Attack Has STOPPED The Shipments Of A Huge Variety Of Items & Includes @americold In The U.S.
CORRECTION: @americold Is Not The Correct Twitter Handle It Is @americoldtweets!
Read 5 tweets
6 Nov
AS I WARNED 1 DAY AGO! THIS IS HOW THE 2ND CIVIL WAR STARTS!
Here We Have The #Marxist #Democrats Preparing To Round-Up & Punish Nearly 70 Million Americans For Exercising Their Constitutional Rights To Support, Vote For, & Speak Openly For The Candidate Of Their Choice!
CONTD: Here's Where Top Level #Marxist Members Of @TheDemocrats Are Compiling Their Enemies List!

CONTD: More Top-Level #Marxist Democrats Building An Enemies List!
Read 5 tweets
4 Nov
NOTE: While #Virginia Has Been "Called" For @JoeBiden A Closer Look At The State Shows A MUCH CLOSER Race Than Is Being Portrayed!
I'm NOT SURE That Virginia Should Have Been Called For ANY Candidate YET!

Perhaps I'm Missing Something?
Is There A Weird Mail In Law There?
CONTD: @FoxNews @ChrisStirewalt Just Announced That The FOX Decision Desk Is VERY CONFIDENT In Their Call That @JoeBiden Will Win #Virginia Based On Their Voter Analysis & Ballots Counted So Far.
...I Will Continue To Monitor...
CONTD: A Review Of Dense Urban Areas Of #Virginia Show Why Decision Desks Have Projected Virginia For @JoeBiden. Many Of The Cities In Virginia Have Well Less Than Half Of Their Votes Counted & They Are 70/30 Biden To Trump.
I'll Continue To Watch But It's Likely A Biden Win!
Read 4 tweets
2 Oct
BREAKING: Signalling To The World President @realDonaldTrump Is
IN CONTROL & Our MILITARY IS READY To React To ANY THREAT. The U.S. Airborn Nuclear Command Aircraft Have Been Scrambled & Are Aloft Along The East & West Coast. Telling Enemies BACK OFF!
en.m.wikipedia.org/wiki/Boeing_E-… ImageImage
CONTD: America’s "Doomsday" Nuclear Command Aircraft Scrambled By @DeptofDefense After @realDonaldTrump Tests Positive For #COVID19 Sending A Signal To America's Enemies; DO NOT TRY US!
the-sun.com/news/1569135/a…
CONTD: A THIRD E6 Nuclear Airborn Command Post Has Been Launched & Is Now Over #Texas! This Many E6 Aircraft Aloft & Doing "Real-World Tasking" At One Time Is Very Unusual. ImageImage
Read 4 tweets
25 Sep
REPORT: @TheJusticeDept Release Of Redacted Interview Of @FBI Special Agent #WilliamBarnett Was The Lead Agent On #CrossfireRazor Investigating @GenFlynn.
#Barnett KNEW #Flynn WAS INNOCENT BUT THE SPECIAL COUNSELS OFFICE INVENTED A CRIME IN AN EFFORT TO FRAME @realDonaldTrump! 1
CONTD: Redacted Interview Of @FBI Special Agent #WilliamBarnett (2/13)
CONTD: Redacted Interview Of @FBI Special Agent #WilliamBarnett (3/13)
Read 13 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!