[Heads Up] Was SolarWinds Really A Daisy Supply Chain Attack?



JetBrains-LogoThe NYT just reported the next revelation regarding the SolarWinds hack.  The Russian FSB may have piggybacked on a tool developed by JetBrains, which is based in the Czech Republic.

The NYT said: "Officials are investigating whether the company, founded by three Russian engineers in the Czech Republic with research labs in Russia, was breached and used as a pathway for hackers to insert back doors into the software of an untold number of technology companies."

The exact software that investigators are examining is a JetBrains product called TeamCity, used by SolarWinds, which allows developers to test and exchange software code before its release. JetBrains is considered a predominant tool for developing software. Google, Hewlett-Packard and Citibank are among its customers, and the company is widely used by developers of Android mobile software. JetBrains themselves blogged about this and said they have not been notified and not aware of this investigation. 

KnowBe4 is not using the TeamCity product, but this whole affair does bring to light the enormous third party vendor risk. Remember how antivirus company Kaspersky was penetrated and "owned" by Russian state-sponsored hackers? Trusting your source code to three Russians seems to be an unacceptable risk in these days. 


Request A Demo: Compliance Plus

Old-school compliance training is challenging for organizations to offer, difficult to do right, and is generally very expensive to deliver. In this live one-on-one demo we will show you how easy it is to deliver your compliance training program using Compliance Plus with KnowBe4's training platform.

CMP-Collage-LCompliance Plus gives you:

  • A whole new library with fresh compliance content updated regularly
  • Coverage of legislative requirements, such as HIPAA and many others
  • New-school high-quality customizable modules
  • Short, interactive modules to keep learners focused, newsletters, docs, and posters are all included
  • Completely automated compliance training campaigns with world-class support and extensive reporting

See for yourself how Compliance Plus can help you keep your users on their toes with compliance, risk and workplace safety top of mind!

Request A Demo

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://info.knowbe4.com/compliance-plus-demo



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews