"
data-check-event-based-preview=""
data-is-vertical-video-embed="false"
data-network-id=""
data-publish-date="2021-08-03T17:51:30Z"
data-video-section="business"
data-canonical-url="https://www.cnn.com/videos/business/2021/08/03/solarwinds-ceo-cybersecurity-hacks.cnnbusinesss"
data-branding-key="the-chat-with-julia-chatterley"
data-video-slug="solarwinds ceo cybersecurity hacks"
data-first-publish-slug="solarwinds ceo cybersecurity hacks"
data-video-tags="celebrities,companies,crime, law enforcement and corrections,criminal offenses,cyberterrorism,digital crime,digital security,international relations and national security,julia chatterley,national security,solarwinds,technology,terrorism,terrorism and counter-terrorism,unrest, conflicts and war"
data-details="">
Video Ad Feedback
SolarWinds CEO: Cyber threats need community vigilance
"
data-check-event-based-preview=""
data-is-vertical-video-embed="false"
data-network-id=""
data-publish-date="2021-08-03T17:51:30Z"
data-video-section="business"
data-canonical-url="https://www.cnn.com/videos/business/2021/08/03/solarwinds-ceo-cybersecurity-hacks.cnnbusinesss"
data-branding-key="the-chat-with-julia-chatterley"
data-video-slug="solarwinds ceo cybersecurity hacks"
data-first-publish-slug="solarwinds ceo cybersecurity hacks"
data-video-tags="celebrities,companies,crime, law enforcement and corrections,criminal offenses,cyberterrorism,digital crime,digital security,international relations and national security,julia chatterley,national security,solarwinds,technology,terrorism,terrorism and counter-terrorism,unrest, conflicts and war"
data-details="">
Video Ad Feedback
SolarWinds CEO: Cyber threats need community vigilance
"
data-check-event-based-preview=""
data-is-vertical-video-embed="false"
data-network-id=""
data-publish-date="2024-03-31T00:30:19Z"
data-video-section="business"
data-canonical-url="https://www.cnn.com/videos/business/2024/03/30/cocoa-chocolate-pricing-surge-easter-rodriguez-nr-vpx.cnn"
data-branding-key=""
data-video-slug="cocoa chocolate pricing surge easter rodriguez nr vpx"
data-first-publish-slug="cocoa chocolate pricing surge easter rodriguez nr vpx"
data-video-tags="agricultural commodities,agriculture,agriculture, forestry, and commercial fishing,banking, finance and investments,business and industry sectors,business, economy and trade,commodity markets,consumer products,domestic alerts,domestic-business,easter,financial markets and investing,food and drink,food products,holidays and observances,iab-agriculture,iab-business,iab-business and finance,iab-business banking & finance,iab-commodities,iab-desserts and baking,iab-economy,iab-financial industry,iab-food & drink,iab-industries,international alerts,international-business,kinds of foods and beverages,price increases,sweets and desserts"
data-details="">
"
data-check-event-based-preview=""
data-is-vertical-video-embed="false"
data-network-id=""
data-publish-date="2024-03-22T12:43:25Z"
data-video-section="business"
data-canonical-url="https://www.cnn.com/videos/business/2024/03/22/trump-truth-social-prepares-to-go-public-egan-cnntm-vpx.cnn"
data-branding-key=""
data-video-slug="trump truth social prepares to go public egan cnntm vpx"
data-first-publish-slug="trump truth social prepares to go public egan cnntm vpx"
data-video-tags="companies,domestic alerts,domestic-business,domestic-us politics,donald trump,iab-computing,iab-internet,iab-politics,iab-social networking,iab-technology & computing,international alerts,international-business,international-us politics,political figures - us,social media,society,trump media & technology group"
data-details="">
Video Ad Feedback
Donald Trump may be on the verge of a massive financial win
"
data-check-event-based-preview=""
data-is-vertical-video-embed="false"
data-network-id=""
data-publish-date="2024-03-21T05:30:53Z"
data-video-section="business"
data-canonical-url="https://www.cnn.com/videos/business/2024/03/21/china-nongfu-spring-boycott-stewart-lkl-hnk-vpx.cnn"
data-branding-key=""
data-video-slug="china nongfu spring boycott stewart lkl hnk vpx"
data-first-publish-slug="china nongfu spring boycott stewart lkl hnk vpx"
data-video-tags="beverages,bottled water,boycotts,business and industry sectors,business, economy and trade,consumer products,food and drink,iab-food & drink,iab-non-alcoholic beverages,kinds of foods and beverages"
data-details="">
Video Ad Feedback
See why some Chinese people are boycotting a popular brand
Nobelium, the Russian hacking group responsible for breaching SolarWinds, is still at it.
The Russian hackers behind that successful 2020 breach of US federal agencies compromised as many as 14 technology firms since May as part of another apparent espionage campaign, Microsoft said Monday.
The hackers have been hitting a different part of the supply chain than in the 2020 breach: companies that buy and distribute software and manage cloud computing services. Microsoft did not name the victim companies or identify the ultimate targets of the alleged Russian spies.
The Microsoft statement follows CNN’s reporting earlier this month that the Russian hacking group had been leveraging compromised technology vendors to try to infiltrate US and European government networks in previously unreported activity.
“This recent activity is another indicator that Russia is trying to gain long-term, systematic access to a variety of points in the technology supply chain and establish a mechanism for surveilling – now or in the future – targets of interest to the Russian government,” said Tom Burt, Microsoft’s corporate vice president, customer security and trust.
The hackers have tried to break into more than 140 software resellers and other tech firms through common techniques such as phishing, according to Microsoft. The ultimate goal is to “impersonate an organization’s trusted technology partner to gain access to their downstream customers,” Burt said.
It’s the latest insight on a Russian group that has in the last two years confounded US government and corporate defenses.
The hackers are best known for using tampered software made by federal contractor SolarWinds to breach at least nine US agencies in activity that came to light in December 2020. The attackers were undetected for months in the unclassified email networks of the departments of Justice, Homeland Security and others.
The Biden administration in April attributed the spying campaign to Russia’s foreign intelligence service, the SVR, and criticized Moscow for exposing thousands of SolarWinds customers to malicious code. Moscow has denied involvement.
The suspected Russian operatives often cast a wide net of potential victims before sifting through them for valuable targets. That’s what happened in May when the hackers impersonated a US government agency and sent malicious emails to 150 organizations in 24 countries, according to Microsoft. Among the apparent targets of that spying campaign were an ex-US ambassador to Russia and anti-corruption activists in Ukraine. Microsoft said that Nobelium targeted 3,000 email accounts at various organizations — most of which were in the United States.
Rob Joyce, head of the National Security Agency’s Cybersecurity Directorate, on Monday morning shared the Microsoft announcement on Twitter and urged organizations to follow Microsoft’s security recommendations.
Defense Secretary Lloyd Austin has previously told CNN the US has “offensive options” to respond to cyberattacks but didn’t specify.
Cybersecurity has been a major focus for the US government following the revelations that hackers had put malicious code into a tool published by SolarWinds. A ransomware attack in May that led to the shutdown of one of America’s most important pieces of energy infrastructure — the Colonial Pipeline — only underscored the importance of the issue.
– CNN Business’ Jordan Valinsky contributed to this report