One-line: Attackers hid a backdoor inside a trusted software update, so thousands of organizations infected themselves by installing it.
The integrity of SolarWinds Orion, network-management software used by about 300,000 customers, including U.S. government agencies and large companies.
A software supply chain weakness. Attackers compromised SolarWinds’ build system and inserted malicious code into legitimate, digitally signed Orion updates.
Starting in early 2020, attackers (attributed to a Russian state intelligence service) injected a backdoor known as SUNBURST into Orion updates. When customers installed the normal update, they installed the backdoor too. About 18,000 of 300,000 customers received the trojanized version. It was publicly disclosed in December 2020.
Integrity first (a trusted update was secretly altered), leading to loss of Confidentiality as attackers accessed victim networks.
About 18,000 organizations downloaded the malicious update, including multiple U.S. federal agencies. It is considered one of the most significant supply-chain attacks to date and prompted a major government response.