SolarWinds Supply-chain Attack — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 16, 2025
Last Seen
December 16, 2025

SolarWinds Supply-chain Attack is a high-profile cyber-espionage campaign in which threat actors compromised SolarWinds' Orion software updates to deliver a backdoor, enabling long-term access to thousands of victims including government agencies and major enterprises.

Overview

SolarWinds Supply-chain Attack is a high-profile cyber-espionage campaign in which threat actors compromised SolarWinds' Orion software updates to deliver a backdoor, enabling long-term access to thousands of victims including government agencies and major enterprises. It illuminated the critical risk of software supply chain compromises and the challenges in detecting malicious updates, driving widespread changes in defense practices and threat intelligence.

Related Threat Clusters

  • Microsoft to Retire RC4 Cipher in Active Directory by 2026

    Microsoft is set to retire the RC4 cipher for administrative authentication in Active Directory by 2026. This decision addresses vulnerabilities that have been exploited in significant cyberattacks over the past decade.…

    3 articles · Updated December 17, 2025

Recent Intelligence Reports

  • Microsoft to Retire Vulnerable RC4 Cipher in Active Directory by 2026 — Webpronews · December 16, 2025

CVSS v3.1 Breakdown