Tech execs face round two of Congressional grilling over SolarWinds breach

Hackers allegedly working for Moscow surreptitiously subverted SolarWinds' software to infiltrate their targets, spending months inside government networks before they were identified

February 26, 2021 07:03 pm | Updated 07:12 pm IST - WASHINGTON, Feb 26

Some have alleged that lax security practices at SolarWinds led to the breach.

Some have alleged that lax security practices at SolarWinds led to the breach.

(Subscribe to our Today's Cache newsletter for a quick snapshot of top 5 tech stories. Click here to subscribe for free.)

Cybersecurity executives are due to face their second round of Congressional questions on Friday over their companies' roles in the sprawling series of digital intrusions blamed on the Russian government.

Texas software company SolarWinds Corp's Chief Executive Sudhakar Ramakrishna, Microsoft Corp President Brad Smith, and FireEye Inc Chief Executive Kevin Mandia were due to address a joint hearing of the House Committees on Oversight and Reform and Homeland Security.

Their appearance comes three days after the trio testified before U.S. senators over the massive breach, which has ensnared nine American government agencies and more than 100 other organizations. SolarWinds' former chief executive - Kevin Thompson, who stepped down shortly before the breach was announced - was also due to testify.

Also Read | U.S. government hack: espionage or act of war?

Hackers allegedly working for Moscow surreptitiously subverted SolarWinds' software to infiltrate their targets, spending months inside government networks before they were identified.

Other techniques - including some still unknown - are believed to have been used as well. Lawmakers and executive branch experts alike are puzzling out how far the hackers got and who might be to blame.

Some have alleged that lax security practices at SolarWinds led to the breach. Others have laid blame at Microsoft's door, saying that a failure to fix known problems with its cloud software authentication infrastructure helped speed the hackers' progress across networks .

Speaking to senators on Tuesday, Microsoft's Smith blamed poor configurations and other controls on the customer's part , including cases "where the keys to the safe and the car were left out in the open."

CrowdStrike Holdings Inc Chief Executive George Kurtz - who addressed senators Tuesday but will not be returning Friday - said Microsoft's "antiquated" architecture was partially responsible.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.