Lessons from Major Supply Chain Incidents
The 2020 SolarWinds SUNBURST attack demonstrated that even deeply trusted software with a legitimate code-signing certificate could be a trojan horse. Attackers compromised the SolarWinds Orion build pipeline and inserted a backdoor into signed updates distributed to approximately 18,000 customers, including US government agencies and critical infrastructure operators. The attack dwelled undetected for months because the malicious code was delivered as a legitimate, digitally-signed software update — it bypassed every perimeter control because it was a trusted package.