Original release date: January 6, 2021
CISA has released Emergency Directive (ED) 21-01 Supplemental Guidance version 3: Mitigate SolarWinds Orion Code Compromise, providing guidance that supersedes Required Action 4 of ED 21-01 and Supplemental Guidance versions 1 and 2.
The updated supplemental guidance also includes forensic analysis and reporting requirements.
CISA has also updated AA20-352A: Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations, originally released December 17, 2020. This update includes new information on initial access vectors, updated mitigation recommendations, and new indicators of compromise (IOCs).
Although the Emergency Directive only applies to Federal Civilian Executive Branch agencies, CISA encourages state and local governments, critical infrastructure entities, and other private sector organizations to review CISA Emergency Directive 21-01 – Supplemental Guidance v.3 for recommendations on operating the SolarWinds Orion Platform. Review the following resources for additional information on the SolarWinds Orion compromise.
This product is provided subject to this Notification and this Privacy & Use policy.
CISA released nineteen Industrial Control Systems (ICS) advisories on November 14, 2024. These advisories provide…
Palo Alto Networks (PAN) has released an important informational bulletin on securing management interfaces after…
Citrix released security updates to address multiple vulnerabilities in NetScaler ADC, NetScaler Gateway, and Citrix…
CISA released three Industrial Control Systems (ICS) advisories on November 7, 2024. These advisories provide…
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of…
Today, CISA published the Framing Software Component Transparency, created by the Software Bill of Materials (SBOM) Tooling…
This website uses cookies.