CI/CD Compromise 2020 Incident #48 CVE-2020-14005

SolarWinds / Sunburst

Estimated Financial Impact
$1B+ ecosystem
Blast Radius
18K organizations; 9+ federal agencies

What Happened

Russian state-sponsored hackers (APT29) compromised SolarWinds' Orion build environment, injecting the Sunburst backdoor into updates distributed to ~18,000 customers. Actively targeted organizations included the US Treasury, Commerce, State Department, FireEye, Microsoft, Intel, and Cisco. SolarWinds spent $40M+ on remediation; stock fell 40%. PE backers Silver Lake and Thoma Bravo sold $281M in stock before public disclosure.

○

Risk Guard: Partial

ARTIFACT_HASH_MISMATCH provides additional verification layer; build system compromise is hardest class

Risk Guard Check Codes That Flag This Incident

ARTIFACT_HASH_MISMATCH

How Every Tool Performed

0 Caught 1 Partial 5 Missed
Tool Verdict Details
OSS Risk Guard Partial ARTIFACT_HASH_MISMATCH provides additional verification layer; build system compromise is hardest class
Socket Missed Not a package-level attack
Snyk Missed Not a package-level attack
Sonatype (Nexus) Missed Not a package-level attack
Black Duck Missed Not a package-level attack
Endor Labs Missed Not a package-level attack
← Codecov bash uploader Ultralytics YOLO →