SolarWinds hackers stole Mimecast source code
Full article519 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The full scope of the breach could take months to understand.
Attackers behind the SolarWinds hacking campaign successfully stole Mimecast source code as part of their sweeping espionage operation, the email security firm said in an incident report published Tuesday.
The hackers, which U.S. government officials suggested are “likely” Russian actors, “accessed and downloaded a limited number of our source code repositories, but we found no evidence of any modifications to our source code nor do we believe there was any impact on our products,” Mimecast said in the incident report.
Mimecast added that it has replaced all compromised servers and that it has no reason to believe the hackers accessed email or archive content of customers.
Mimecast had previously disclosed that the hackers compromised a security certificate the company used to secure connections. The latest revelation, which comes more than two months after its disclosure the certificate was compromised, now underscores just how long it may take to get a full picture of the hackers’ espionage operation.
Already, the hackers are known to have viewed Microsoft’s source code and stolen security tools FireEye used to test clients’ defenses.
The White House has warned in recent weeks that triaging the damage from the SolarWinds hackers, who laced malicious code in a SolarWinds software update, could take months.
“Many of the private sector compromises are technology companies including networks of companies whose products can be used to launch other intrusions,” Deputy National Security Advisor for Cyber and Emerging Technology Anne Neuberger said during a White House press briefing in February.
As the Biden administration works to respond to SolarWinds and the exploitation of newly disclosed Microsoft Exchange Server vulnerabilities, the federal government is weighing whether it should roll out cybersecurity ratings for software in order to promote secure software practices, one senior administration official told reporters earlier this month.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/solarwinds-hackers-stole-mimecast-source-code/